CVE-2026-95503 MEDIUM

CVE-2026-95503: Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabled

Vendor Red Hat
Product Red Hat Build of Keycloak
Weakness CWE-347
Published September 22, 2026
Last update September 22, 2026

CVSS base score

6.8/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Distribution Center (KDC) by requesting a server ticket. This allows an attacker on the same network to spoof the KDC and bypass the authentication process, potentially gaining unauthorized access to user accounts.

Key dates

02Disclosure timeline

September 22, 2026 CVE published

Related vulnerabilities

04Related CVE