Description
A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request.
Published: 2026-09-23
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Bypass of second-factor authentication
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Conditional OTP authenticator of Keycloak enables an attacker who possesses a user’s password to bypass the one‑time password step by sending a specially crafted HTTP header that is not verified to originate from a trusted source. The vulnerability arises from the OTP skip‑header policy being evaluated against untrusted proxy headers, allowing an attacker to skip the second‑factor requirement and gain access without additional authentication.

Affected Systems

The issue affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7, as documented by the vendor. No specific version ranges are provided in the advisory, so all affected installations that employ the conditional OTP feature must verify whether they are running a patched build.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that the exploitation probability may not be high at present. However, the attack still requires possession of the user password and the ability to supply HTTP headers, implying that an attacker who has compromised credentials can elevate their privileges by manipulating request headers. Because no official workaround is available, the risk remains until a patch is applied.

Generated by OpenCVE AI on September 23, 2026 at 13:53 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the latest Red Hat Build of Keycloak release that contains the patch for the OTP skip‑header header validation flaw.
  • Update any Red Hat Single Sign‑On 7 deployments to a version that includes the same mitigation for the conditional OTP feature.
  • Temporarily disable the conditional OTP skip‑header policy or restrict the set of trusted proxy headers until the vendor releases an update.

Generated by OpenCVE AI on September 23, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request.
Title Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-287
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-23T11:12:46.785Z

Reserved: 2026-09-23T09:30:31.113Z

Link: CVE-2026-96445

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T12:17:08.773

Modified: 2026-09-23T12:17:08.773

Link: CVE-2026-96445

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-22T15:35:51Z

Links: CVE-2026-96445 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:00:05Z

Weaknesses