CVE-2026-16093: Red Hat Build Of Keycloak
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.
Affected products
- Red Hat Build Of Keycloak: affected versions not specified
- Red Hat Data Grid: version 8.0 only
- Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
- Red Hat Single Sign-On: version 7.0 only
Published 2026-07-17. Last modified 2026-09-16.