No analysis available yet.
Vendor Workaround
To mitigate this issue, Keycloak administrators should review and adjust client policies designed to reject Resource Owner Password Credentials (ROPC) grants. Avoid using the `client-type`, `client-roles`, `client-attributes`, or `client-scopes` condition providers in conjunction with the `reject-ropc-grant` executor. Instead, configure policies to use the `grant-type` condition provider for ROPC rejection. A restart or reload of the Keycloak service may be required for these policy changes to take full effect.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 28 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password Credentials (ROPC) grant, even when a policy is explicitly configured to block it. This bypass can lead to unauthorized access and information disclosure. | |
| Title | Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-280 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-05-28T03:44:18.671Z
Reserved: 2026-05-28T03:09:25.012Z
Link: CVE-2026-9792
No data.
Status : Received
Published: 2026-05-28T05:16:40.537
Modified: 2026-05-28T05:16:40.537
Link: CVE-2026-9792
No data.
OpenCVE Enrichment
No data.