Vulnerability Description
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:68276
- https://access.redhat.com/errata/RHSA-2026:68277
- https://access.redhat.com/errata/RHSA-2026:68278
- https://access.redhat.com/errata/RHSA-2026:68280
- https://access.redhat.com/security/cve/CVE-2026-74909
- https://bugzilla.redhat.com/show_bug.cgi?id=2517354
FAQ
What is CVE-2026-74909?
CVE-2026-74909 is a vulnerability with a CVSS score of 8.1 (HIGH). Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web ad...
How severe is CVE-2026-74909?
CVE-2026-74909 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-74909?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.