CVE-2026-97176
📛 CVE Title
Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator
Description
A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- redhat
- CVSS severity
- MEDIUM
- CVSS score
- 4.2 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N- Effective score
- 4.2 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-862 - Reserved
- 2026-09-24
- Published
- 2026-09-24 05:47 UTC
- Last updated
- 2026-09-24 05:47 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/97xxx/CVE-2026-97176.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-24 06:17:04 UTC
- NVD last modified
- 2026-09-24 14:51:56 UTC
- NVD CVSS v3.1
- 4.2 / 10 MEDIUM source: secalert@redhat.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N- Exploitability subscore
- 1.6 / 10
- Impact subscore
- 2.5 / 10
- EPSS score
- 0.0017 (probability of exploitation in next 30 days)
- EPSS percentile
- 5.29% vs all CVEs — higher = more likely to be exploited, as of 2026-09-24
NVD / KEV / EPSS data refreshed 2026-09-25 04:27 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85792 - Assigner
- redhat
- Published
- Sep 24, 2026, 5:47:52 AM
- Updated
- Sep 24, 2026, 5:47:52 AM
- EUVD base score (CVSS 3.1)
-
4.2 / 10
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - EUVD-reported EPSS
- 0.1700
- Aliases
-
GHSA-5jw9-cc9v-8h8r
ENISA description: A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.
Affected products (3)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | — | — |
| Red Hat | Red Hat Build of Keycloak | — | — |
| Red Hat | Red Hat Single Sign-On 7 | — | — |
Vendor references (2)
References embedded in the original CVE record by the assigning CNA.
- https://access.redhat.com/security/cve/CVE-2026-97176 vdb-entryx_refsource_REDHAT
- RHBZ#2539964 issue-trackingx_refsource_REDHAT
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://access.redhat.com/security/cve/CVE-2026-97176 secalert@redhat.com
- https://bugzilla.redhat.com/show_bug.cgi?id=2539964 secalert@redhat.com
Remediations (10)
-
web:access.redhat.com
A deferred status means that a fix for an affected product version is not guaranteed due to higher-priority development work. Available options depend mostly on the Impact of the vulnerability and the current Life Cycle phase of your product. Overall, you have the following options: Apply a mitigation (if one exists).
2026-09-25 10:43 UTC -
web:anonhaven.com
CVE Details CVE ID CVE-2026-97176 Published Date Sep 24, 2026 Vendor Keycloak Severity MEDIUM CVSS v3.1 Score 4.2
2026-09-25 10:43 UTC -
web:byteiota.com
That's not all. September's Patch Tuesday also fixed two zero-days under active exploitation: CVE - 2026 -85880, a heap buffer overflow in Windows ALPC that allows local privilege escalation to SYSTEM, and CVE - 2026 -81963, a link-following flaw in the Windows Update Stack. Rolling back removes those fixes too.
2026-09-25 10:43 UTC -
web:cvetodo.com
CVE-2026-97176 is a CVSS 4.2 medium-severity vulnerability in Red Hat products. Full technical analysis, mitigations , and exploit status — updated in real time.
2026-09-25 10:43 UTC -
web:patchmypc.com
You can find the production release history below for 2026 .
2026-09-25 10:43 UTC -
web:support.microsoft.com
Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2016. It doesn't apply to the Office 2016 Click-to-Run editions, such as Microsoft Office 365 Home. (See What version of Office am I using?) How to get and install the update Method 1: Microsoft Update This update is available from Microsoft Update. When you turn on ...
2026-09-25 10:43 UTC -
web:vulmon.com
Keycloak Authentication Bypass Allows Unauthorized Access to Sensitive Resources. Keycloak versions with a flaw in their Level of Authentication enforcement…
2026-09-25 10:43 UTC -
web:windowsmanagementexperts.com
The Microsoft September 2026 Patch Tuesday release fixes up to 974 vulnerabilities, including active zero-days. Here's how IT teams should prioritize patching.
2026-09-25 10:43 UTC -
web:www.rapid7.com
CVE-2026-97176 : Red Hat: A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management…. View severity, references, and remediation details from Rapid7.
2026-09-25 10:43 UTC -
web:www.tenable.com
Details Source: Mitre, NVD Published: 2026 -09-24 Updated: 2026 -09-24
2026-09-25 10:43 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-97176.json.
{
"containers": {
"cna": {
"affected": [
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:build_keycloak:"
],
"defaultStatus": "affected",
"packageName": "keycloak-services",
"product": "Red Hat Build of Keycloak",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:build_keycloak:"
],
"defaultStatus": "affected",
"packageName": "rhbk/keycloak-rhel9",
"product": "Red Hat Build of Keycloak",
"vendor": "Red Hat"
},
{
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"cpes": [
"cpe:/a:redhat:red_hat_single_sign_on:7"
],
"defaultStatus": "unaffected",
"packageName": "keycloak-services",
"product": "Red Hat Single Sign-On 7",
"vendor": "Red Hat"
}
],
"credits": [
{
"lang": "en",
"value": "Red Hat would like to thank Amaury Cormier (GitHub: Mandrak-Kimigo) for reporting this issue."
}
],
"datePublic": "2026-09-23T14:37:51.000Z",
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims."
}
],
"metrics": [
{
"other": {
"content": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"value": "Moderate"
},
"type": "Red Hat severity rating"
}
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.2,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T05:47:52.082Z",
"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"shortName": "redhat"
},
"references": [
{
"tags": [
"vdb-entry",
"x_refsource_REDHAT"
],
"url": "https://access.redhat.com/security/cve/CVE-2026-97176"
},
{
"name": "RHBZ#2539964",
"tags": [
"issue-tracking",
"x_refsource_REDHAT"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2539964"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T14:37:51.000Z",
"value": "Reported to Red Hat."
},
{
"lang": "en",
"time": "2026-09-23T14:37:51.000Z",
"value": "Made public."
}
],
"title": "Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator",
"workarounds": [
{
"lang": "en",
"value": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."
}
],
"x_generator": {
"engine": "cvelib 1.8.0"
},
"x_redhatCweChain": "CWE-862: Missing Authorization"
}
},
"cveMetadata": {
"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
"assignerShortName": "redhat",
"cveId": "CVE-2026-97176",
"datePublished": "2026-09-24T05:47:52.082Z",
"dateReserved": "2026-09-24T05:34:42.463Z",
"dateUpdated": "2026-09-24T05:47:52.082Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}