{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-28T03:15:43Z",
  "bugzilla" : {
    "description" : "keycloak: Keycloak: Information disclosure via SAML ECP endpoint",
    "id" : "2482461",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2482461"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-209",
  "details" : [ "A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.", "A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure." ],
  "statement" : "This Moderate-severity information disclosure flaw in Keycloak allows an unauthenticated, remote attacker to enumerate client protocol types. By sending specially crafted SOAP requests to the SAML ECP endpoint and analyzing the resulting faultstrings, an attacker can discern the protocol associated with different client IDs, aiding in further targeted attacks.",
  "acknowledgement" : "Red Hat would like to thank Asaad Mostafa and Muhammed Hussein for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat build of Keycloak 26.4",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:30050",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk/keycloak-operator-bundle:26.4.13-1"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.4",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:30050",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk/keycloak-rhel9:26.4-19"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.4",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:30050",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk/keycloak-rhel9-operator:26.4-19"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.4.13",
    "release_date" : "2026-06-25T00:00:00Z",
    "advisory" : "RHSA-2026:30049",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk/keycloak-rhel9"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25097",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-operator-bundle:26.6.3-3"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25097",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-rhel9:26.6-6"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25097",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-rhel9-operator:26.6-6"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6.3",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25098",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-rhel9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-9794\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9794" ],
  "name" : "CVE-2026-9794",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}