CVE-2026-16093: Red Hat Build Of Keycloak

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.

Affected products

  • Red Hat Build Of Keycloak: affected versions not specified
  • Red Hat Data Grid: version 8.0 only
  • Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
  • Red Hat Single Sign-On: version 7.0 only

Published 2026-07-17. Last modified 2026-09-16.