Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims. | |
| Title | Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-24T05:47:52.082Z
Reserved: 2026-09-24T05:34:42.463Z
Link: CVE-2026-97176
No data.
Status : Received
Published: 2026-09-24T06:17:04.227
Modified: 2026-09-24T06:17:04.227
Link: CVE-2026-97176
No data.
OpenCVE Enrichment
Updated: 2026-09-24T07:30:16Z
