CVE-2026-96446 vulnerability in Red Hat Products
Published on September 23, 2026
Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path
A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request URI is used only once is not enforced. An attacker could potentially reuse a request URI to obtain multiple authorization codes for a user who is already signed in, violating security standards like FAPI-2.
Vulnerability Analysis
CVE-2026-96446 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-96446 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-96446
stack.watch emails you whenever new vulnerabilities are published in Red Hat Build Keycloak or Red Hat Single Sign On. Just hit a watch button to start following.