Keycloak: keycloak: brute-force protection bypass in ciba flow
Published May 28, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.49%
Description
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brute-force protection. This allows continued authentication attempts and token issuance even when the account should be locked, potentially enabling further unauthorized access attempts.
Affected products
No data.
- n/a
No data.
Red Hat build of Keycloak 26.4
rhbk/keycloak-operator-bundle:26.4.14-1
Fixed · RHSA-2026:50847
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9-operator:26.4-22
Fixed · RHSA-2026:50847
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9:26.4-22
Fixed · RHSA-2026:50847
Red Hat build of Keycloak 26.4.14
rhbk/keycloak-rhel9
Fixed · RHSA-2026:50846
Red Hat build of Keycloak 26.6
rhbk/keycloak-operator-bundle:26.6.5-1
Fixed · RHSA-2026:50849
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9-operator:26.6-11
Fixed · RHSA-2026:50849
Red Hat build of Keycloak 26.6
rhbk/keycloak-rhel9:26.6-11
Fixed · RHSA-2026:50849
Red Hat build of Keycloak 26.6.5
n/a
Fixed · RHSA-2026:50848
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.14-1 | Fixed | RHSA-2026:50847 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator:26.4-22 | Fixed | RHSA-2026:50847 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9:26.4-22 | Fixed | RHSA-2026:50847 |
| Red Hat build of Keycloak 26.4.14 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:50846 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle:26.6.5-1 | Fixed | RHSA-2026:50849 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9-operator:26.6-11 | Fixed | RHSA-2026:50849 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-rhel9:26.6-11 | Fixed | RHSA-2026:50849 |
| Red Hat build of Keycloak 26.6.5 | n/a | Fixed | RHSA-2026:50848 |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, ensure that Client-Initiated Backchannel Authentication (CIBA) is not enabled in Keycloak realms unless explicitly required. If CIBA is enabled, consider disabling it to prevent the bypass of brute-force protection mechanisms. Consult Keycloak documentation for instructions on managing CIBA configuration.
Red Hat statement
This flaw in Keycloak's Client-Initiated Backchannel Authentication (CIBA) flow is rated as Low impact. The vulnerability allows bypassing brute-force protection when a user account is locked, but only if CIBA is explicitly enabled and configured (non-default), and the user approves the authentication request on their device. This significantly limits the attack surface in typical Red Hat deployments where CIBA is not enabled by default.
Red Hat mitigation
To mitigate this issue, ensure that Client-Initiated Backchannel Authentication (CIBA) is not enabled in Keycloak realms unless explicitly required. If CIBA is enabled, consider disabling it to prevent the bypass of brute-force protection mechanisms. Consult Keycloak documentation for instructions on managing CIBA configuration.
References (16)
- https://access.redhat.com/errata/RHSA-2026:50846 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:50847 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:50848 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:50849 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-9798 vdb-entryx_refsource_REDHATMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2482470 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-q6h7-xxp7-7429 Advisory
- https://github.com/keycloak/keycloak/commit/11c2695064cd93da1d333df3f69d4a4141e86c29
- https://github.com/keycloak/keycloak/commit/2edc6b112e2dedce63062b89ab3c7ae542e0d9ac
- https://github.com/keycloak/keycloak/commit/a11e3254efc16ae72ce5092b93b9f557a4ba43ae
- https://github.com/keycloak/keycloak/issues/49432
- https://github.com/keycloak/keycloak/pull/49791
- https://github.com/keycloak/keycloak/pull/49903
- https://github.com/keycloak/keycloak/pull/49905
- https://nvd.nist.gov/vuln/detail/CVE-2026-9798
- https://www.cve.org/CVERecord?id=CVE-2026-9798
Change history (0)
No recorded changes yet.