CVE detail
CVE-2026-9792
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently bypassed. This allows an unauthenticated remote attacker to obtain tokens via a Resource Owner Password Credentials (ROPC) grant, even when a policy is explicitly configured to block it. This bypass can lead to unauthorized access and information disclosure.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://bugzilla.redhat.com/show_bug.cgi?id=2482459bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 28, 2026, 5:16 AM - https://access.redhat.com/security/cve/CVE-2026-9792access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 28, 2026, 5:16 AM - https://access.redhat.com/errata/RHSA-2026:30050access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 28, 2026, 5:16 AM - https://access.redhat.com/errata/RHSA-2026:30049access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 28, 2026, 5:16 AM - https://access.redhat.com/errata/RHSA-2026:25098access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 28, 2026, 5:16 AM - https://access.redhat.com/errata/RHSA-2026:25097access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 28, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-3190CVSS 4.3 · Medium
A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any au…
- CVE-2026-11804CVSS 5.2 · Medium
Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linu…
- CVE-2026-62393CVSS 4.3 · Medium
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to…
- CVE-2026-45196CVSS 7.8 · High
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.
- CVE-2026-54262CVSS 4.3 · Medium
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can…
- CVE-2026-54261CVSS 6.5 · Medium
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint,…