# Keycloak versions 26.2.x through 26.5.x contain a vulnerability allowing attackers to…

Published: 2026-06-01 · Severity: high
Canonical: https://vorant.io/reports/7117f0d8-ae4f-450d-b324-9dca34ff11d0/keycloak-versions-26-2-x-through-26-5-x-contain-a-vulnerability-allowing

> Keycloak versions 26.2.x through 26.5.x contain a vulnerability allowing attackers to bypass security policies and compromise data confidentiality.

A security vulnerability has been identified in Keycloak, an open-source identity and access management solution. The flaw affects multiple version branches: 26.2.x prior to 26.2.14, 26.4.x prior to 26.4.10, and 26.5.x prior to 26.5.5. Exploitation of this vulnerability enables an attacker to circumvent the application's security policy controls and gain unauthorized access to confidential data.

The French CERT (CERT-FR) has issued an advisory recommending immediate patching to address this issue. The vulnerability is tracked as CVE-2026-2092 and documented in GitHub Security Advisory GHSA-794g-x443-36f7. Organizations running affected Keycloak versions should prioritize upgrading to the patched releases to prevent potential data breaches and security policy bypasses.

Given Keycloak's widespread use for authentication and authorization in enterprise environments, this vulnerability poses significant risk to organizations that have not yet applied the available patches. The impact is particularly concerning for environments where Keycloak protects sensitive resources or manages access controls for critical systems.

## Mentioned in this report

- Vulnerabilities: CVE-2026-2092

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0669

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7117f0d8-ae4f-450d-b324-9dca34ff11d0/keycloak-versions-26-2-x-through-26-5-x-contain-a-vulnerability-allowing.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
