CVE-2026-74909 vulnerability in Red Hat Products
Published on September 16, 2026
Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer into applying a less restrictive security policy than intended, potentially gaining unauthorized access to sensitive administrative or private application endpoints.
Vulnerability Analysis
CVE-2026-74909 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 34 days later.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-74909 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-74909
stack.watch emails you whenever new vulnerabilities are published in Red Hat Build Keycloak or Red Hat Single Sign On. Just hit a watch button to start following.
Affected Versions
Red Hat build of Keycloak 26.4:- Version 26.4-26 and below * is unaffected.
- Version 26.4-26 and below * is unaffected.
- Version 26.4.16-2 and below * is unaffected.
- Version 26.6-20 and below * is unaffected.
- Version 26.6.7-3 and below * is unaffected.
- Version 26.6-20 and below * is unaffected.