# Keycloak patches 8 flaws including RCE

Published: 2026-06-29 · Severity: high
Canonical: https://vorant.io/reports/8f372df7-4398-5436-8dd8-6d103248a376/keycloak-patches-8-flaws-including-rce

> Multiple vulnerabilities in Keycloak versions 26.0.x and 26.6.x enable remote code execution, privilege escalation, and data confidentiality breaches.

The French CERT (CERT-FR) has issued an advisory concerning multiple security vulnerabilities discovered in Red Hat Keycloak, an open-source identity and access management solution. The flaws affect Keycloak versions 26.0.x prior to 26.0.10 and versions 26.6.x prior to 26.6.4. Eight security advisories were published on June 26, 2026, detailing the vulnerabilities.

The vulnerabilities enable several attack vectors including remote arbitrary code execution, privilege escalation, cross-site scripting (XSS), security policy bypass, and compromise of data confidentiality and integrity. Given Keycloak's role as an authentication and authorization gateway for enterprise applications, successful exploitation could grant attackers elevated access to protected resources and systems.

Organizations running affected Keycloak versions should prioritize patching to versions 26.0.10 or 26.6.4 as appropriate. The vendor has released security bulletins for each vulnerability along with corresponding CVE identifiers, providing detailed remediation guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2026-11800, CVE-2026-9083, CVE-2026-9086, CVE-2026-9099, CVE-2026-9705, CVE-2026-9795, CVE-2026-9799, CVE-2026-9800

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0815/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8f372df7-4398-5436-8dd8-6d103248a376/keycloak-patches-8-flaws-including-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
