CVE-2026-96445 vulnerability in Red Hat Products
Published on September 23, 2026
Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers
A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request.
Vulnerability Analysis
CVE-2026-96445 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-96445 has been classified to as an authentification vulnerability or weakness.
Products Associated with CVE-2026-96445
stack.watch emails you whenever new vulnerabilities are published in Red Hat Build Keycloak or Red Hat Single Sign On. Just hit a watch button to start following.