MEDIUM 4.2 NVD
CVE-2026-97176
A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client sp
A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.
References
- https://access.redhat.com/security/cve/CVE-2026-97176
- https://bugzilla.redhat.com/show_bug.cgi?id=2539964
This medium severity vulnerability with a CVSS score of 4.2 was published on 2026-09-24 via NVD.
vulnfeed aggregates 11940 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.