CVE-2026-9798: Keycloak: keycloak: brute-force protection bypass in ciba flow
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9798?
CVE-2026-9798 has a medium severity rating of 4.3.
How does CVE-2026-9798 affect Keycloak users?
CVE-2026-9798 allows attackers with valid client credentials to bypass brute-force protection during the CIBA flow.
What are the potential impacts of CVE-2026-9798?
Exploitation of CVE-2026-9798 can lead to unauthorized access to locked user accounts.
How can I mitigate CVE-2026-9798 in Keycloak?
To mitigate CVE-2026-9798, ensure that your Keycloak instance is updated to the latest version that addresses this vulnerability.
What version of Keycloak is affected by CVE-2026-9798?
CVE-2026-9798 affects Keycloak versions that implement the CIBA flow allowing brute-force protection bypass.