CVE-2026-9800
Redhat Build Of Keycloak 26.4 – 26.4.13
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NSummary
CVE-2026-9800 is a high-severity Comparison Using Wrong Factors (CWE-1025) vulnerability in Redhat Build Of Keycloak. Its CVSS base score is 8.1 (High).
Operationally, ranked at the 29th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and SA-15 (Development Process, Standards, and Tools) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-39471
Vulnerability Data
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either…
more
as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Developer testing and evaluation can discover incorrect comparison logic after implementation but does not stop the flaw from being written.
Requiring a documented development process and tools can embed standards that reduce introduction of erroneous comparison factors.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC activities such as code review and logic testing directly prevent incorrect comparison factors in code.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect incorrect comparison results during development and acceptance.
Secure development lifecycle includes requirements and reviews that can catch incorrect comparison logic.
Application security requirements can specify correct comparison criteria and validation rules.
Secure coding standards directly address proper comparison logic and factor selection.