s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-97176

📛 CVE Title

Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator

Description

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.

Overview

State
PUBLISHED
Assigner (CNA)
redhat
CVSS severity
MEDIUM
CVSS score
CVSS 4.2 / 10 4.2 4.2 / 10
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Effective score
4.2 / 10 MEDIUM source: CNA overview
CWE(s)
CWE-862
Reserved
2026-09-24
Published
2026-09-24 05:47 UTC
Last updated
2026-09-24 05:47 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97176.json

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-09-24 06:17:04 UTC
NVD last modified
2026-09-24 14:51:56 UTC
NVD CVSS v3.1
CVSS 4.2 / 10 4.2 4.2 / 10 MEDIUM source: secalert@redhat.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability subscore
1.6 / 10
Impact subscore
2.5 / 10
EPSS score
0.0017 (probability of exploitation in next 30 days)
EPSS percentile
5.29% vs all CVEs — higher = more likely to be exploited, as of 2026-09-24

NVD / KEV / EPSS data refreshed 2026-09-25 04:27 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-85792
Assigner
redhat
Published
Sep 24, 2026, 5:47:52 AM
Updated
Sep 24, 2026, 5:47:52 AM
EUVD base score (CVSS 3.1)
4.2 / 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
EUVD-reported EPSS
0.1700
Aliases
GHSA-5jw9-cc9v-8h8r

ENISA description: A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.

EUVD references (2)

Affected products (3)

VendorProductVersionsPlatforms
Red Hat Red Hat Build of Keycloak — —
Red Hat Red Hat Build of Keycloak — —
Red Hat Red Hat Single Sign-On 7 — —

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

  • web:access.redhat.com

    A deferred status means that a fix for an affected product version is not guaranteed due to higher-priority development work. Available options depend mostly on the Impact of the vulnerability and the current Life Cycle phase of your product. Overall, you have the following options: Apply a mitigation (if one exists).

    2026-09-25 10:43 UTC
  • web:anonhaven.com

    CVE Details CVE ID CVE-2026-97176 Published Date Sep 24, 2026 Vendor Keycloak Severity MEDIUM CVSS v3.1 Score 4.2

    2026-09-25 10:43 UTC
  • web:byteiota.com

    That's not all. September's Patch Tuesday also fixed two zero-days under active exploitation: CVE - 2026 -85880, a heap buffer overflow in Windows ALPC that allows local privilege escalation to SYSTEM, and CVE - 2026 -81963, a link-following flaw in the Windows Update Stack. Rolling back removes those fixes too.

    2026-09-25 10:43 UTC
  • web:cvetodo.com

    CVE-2026-97176 is a CVSS 4.2 medium-severity vulnerability in Red Hat products. Full technical analysis, mitigations , and exploit status — updated in real time.

    2026-09-25 10:43 UTC
  • web:patchmypc.com

    You can find the production release history below for 2026 .

    2026-09-25 10:43 UTC
  • web:support.microsoft.com

    Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2016. It doesn't apply to the Office 2016 Click-to-Run editions, such as Microsoft Office 365 Home. (See What version of Office am I using?) How to get and install the update Method 1: Microsoft Update This update is available from Microsoft Update. When you turn on ...

    2026-09-25 10:43 UTC
  • web:vulmon.com

    Keycloak Authentication Bypass Allows Unauthorized Access to Sensitive Resources. Keycloak versions with a flaw in their Level of Authentication enforcement…

    2026-09-25 10:43 UTC
  • web:windowsmanagementexperts.com

    The Microsoft September 2026 Patch Tuesday release fixes up to 974 vulnerabilities, including active zero-days. Here's how IT teams should prioritize patching.

    2026-09-25 10:43 UTC
  • web:www.rapid7.com

    CVE-2026-97176 : Red Hat: A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management…. View severity, references, and remediation details from Rapid7.

    2026-09-25 10:43 UTC
  • web:www.tenable.com

    Details Source: Mitre, NVD Published: 2026 -09-24 Updated: 2026 -09-24

    2026-09-25 10:43 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-97176.json.

{
  "containers": {
    "cna": {
      "affected": [
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:build_keycloak:"
          ],
          "defaultStatus": "affected",
          "packageName": "keycloak-services",
          "product": "Red Hat Build of Keycloak",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:build_keycloak:"
          ],
          "defaultStatus": "affected",
          "packageName": "rhbk/keycloak-rhel9",
          "product": "Red Hat Build of Keycloak",
          "vendor": "Red Hat"
        },
        {
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7"
          ],
          "defaultStatus": "unaffected",
          "packageName": "keycloak-services",
          "product": "Red Hat Single Sign-On 7",
          "vendor": "Red Hat"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Red Hat would like to thank Amaury Cormier (GitHub: Mandrak-Kimigo) for reporting this issue."
        }
      ],
      "datePublic": "2026-09-23T14:37:51.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims."
        }
      ],
      "metrics": [
        {
          "other": {
            "content": {
              "namespace": "https://access.redhat.com/security/updates/classification/",
              "value": "Moderate"
            },
            "type": "Red Hat severity rating"
          }
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-862",
              "description": "Missing Authorization",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T05:47:52.082Z",
        "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "shortName": "redhat"
      },
      "references": [
        {
          "tags": [
            "vdb-entry",
            "x_refsource_REDHAT"
          ],
          "url": "https://access.redhat.com/security/cve/CVE-2026-97176"
        },
        {
          "name": "RHBZ#2539964",
          "tags": [
            "issue-tracking",
            "x_refsource_REDHAT"
          ],
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539964"
        }
      ],
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-23T14:37:51.000Z",
          "value": "Reported to Red Hat."
        },
        {
          "lang": "en",
          "time": "2026-09-23T14:37:51.000Z",
          "value": "Made public."
        }
      ],
      "title": "Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator",
      "workarounds": [
        {
          "lang": "en",
          "value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."
        }
      ],
      "x_generator": {
        "engine": "cvelib 1.8.0"
      },
      "x_redhatCweChain": "CWE-862: Missing Authorization"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
    "assignerShortName": "redhat",
    "cveId": "CVE-2026-97176",
    "datePublished": "2026-09-24T05:47:52.082Z",
    "dateReserved": "2026-09-24T05:34:42.463Z",
    "dateUpdated": "2026-09-24T05:47:52.082Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}