SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16093

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Keycloak's Client Policies mechanism is vulnerable to a bypass that allows attackers with valid client credentials to authenticate using unsigned assertions, circumventing security requirements for signed JWTs. This flaw could lead to unauthorized access, undermining the intended security posture of applications relying on Keycloak for authentication. Organizations utilizing Keycloak for client authentication should prioritize addressing this vulnerability to maintain robust security controls.

CVE
CVE-2026-16093
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%

Original NVD Description

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)