VORANT. Threat Intelligence Sign in Get the full feed

CERT-FR flags Keycloak security bypass flaw

routine vulnerability technology

A vulnerability in Keycloak 26.7.x before 26.7.4 allows an attacker to bypass security policy enforcement.

CERT-FR issued an advisory regarding a vulnerability in Keycloak, the open-source identity and access management platform, affecting versions 26.7.x prior to 26.7.4. The flaw allows an attacker to bypass the security policy, though the advisory does not detail the exact mechanism or the attacker's required access level. This was published alongside an upstream GitHub Security Advisory (GHSA-xpwp-2pcm-8xq3) and assigned CVE-2026-90997.

No evidence of active exploitation in the wild is mentioned in the bulletin. Defenders running affected Keycloak versions should consult the vendor advisory and CVE record for patch details and upgrade to 26.7.4 or later. Given Keycloak's role as an IAM/SSO provider, a security policy bypass could have downstream implications for authentication and authorization controls across dependent applications, warranting prompt patching even absent confirmed exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-90997

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1195

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free