Skip to main content
Vulnerability Database/CVE-2026-94217

CVE-2026-94217: Keycloak UMA Auth Bypass Vulnerability

CVE-2026-94217 is an authentication bypass flaw in Keycloak User-Managed Access that allows attackers to gain unauthorized access scopes on victim resources. This post explains its impact, affected versions, and mitigation steps.

Updated:

CVE-2026-94217 Overview

CVE-2026-94217 is an authorization flaw in the User-Managed Access (UMA) implementation of Keycloak. The vulnerability resides in the authorization token endpoint when processing permission tickets. When two distinct users own resources sharing the same name, Keycloak incorrectly merges the permissions from both resources during authorization token issuance. An authenticated attacker can request an authorization token and receive access scopes on a victim's resource that were never intended to be shared. The issue is tracked under CWE-862: Missing Authorization.

Critical Impact

Authenticated users can obtain unintended access scopes on other users' UMA-protected resources when resource names collide, leading to cross-tenant authorization bypass.

Affected Products

  • Red Hat Keycloak (UMA authorization component)
  • Red Hat build of Keycloak
  • Red Hat Single Sign-On distributions incorporating the affected UMA implementation

Discovery Timeline

  • 2026-09-21 - CVE-2026-94217 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-94217

Vulnerability Analysis

Keycloak's UMA 2.0 flow allows resource owners to define resources and share scopes through permission tickets. When a requesting party presents a permission ticket to the authorization token endpoint, Keycloak evaluates the ticket against the target resource and issues a Requesting Party Token (RPT) containing granted scopes.

The defect occurs during resource lookup for permission evaluation. The endpoint identifies resources by name without properly disambiguating by owner. When two users each register a resource with the same name, the authorization engine treats the matching entries as a single set and merges their scope grants into the issued RPT. The requester receives scopes attached to another user's resource, breaking tenant isolation within the UMA authorization service.

Exploitation requires an authenticated account and user interaction, as reflected in the CVSS vector. Impact is limited to integrity: an attacker can gain access scopes never intended for them, but confidentiality and availability are not directly affected per the published metrics.

Root Cause

The root cause is missing authorization enforcement during resource resolution in the UMA permission ticket processing path. Resources are matched by name rather than by the composite key of (owner, name), so the authorization engine cannot distinguish between resources owned by different principals when names collide.

Attack Vector

The attack proceeds over the network against the Keycloak authorization token endpoint. An attacker registers a UMA-protected resource with the same name as a victim's resource, then requests a permission ticket and exchanges it at the token endpoint. Keycloak returns an RPT that includes merged scopes from the victim's resource. See the Red Hat CVE-2026-94217 Advisory and Red Hat Bug Report #2537313 for vendor detail.

No public proof-of-concept exploit is currently available.

Detection Methods for CVE-2026-94217

Indicators of Compromise

  • Authorization token responses containing scopes for resources the requesting party does not own
  • Multiple UMA resources sharing identical name values across different owner identifiers in the Keycloak database
  • Unexpected permission claims in issued RPTs referencing resource IDs outside the requester's ownership

Detection Strategies

  • Audit the Keycloak RESOURCE_SERVER_RESOURCE table for name collisions across distinct owners and correlate with recent RPT issuance events.
  • Enable Keycloak event logging for CODE_TO_TOKEN and UMA PERMISSION_TOKEN events and alert on tokens issued with permissions referencing resources not owned by the subject.
  • Ingest Keycloak audit logs into a SIEM and build correlation rules that compare the sub claim of RPT requests with the owner of each returned resource permission.

Monitoring Recommendations

  • Forward Keycloak admin and event logs to a centralized logging platform for retention and query.
  • Track baseline volumes of UMA permission ticket requests per realm and alert on anomalous spikes from single accounts.
  • Monitor for creation of new UMA resources whose names match existing high-value resources in the same realm.

How to Mitigate CVE-2026-94217

Immediate Actions Required

  • Review the Red Hat CVE-2026-94217 Advisory and apply vendor-supplied patches when available for your Keycloak or Red Hat build of Keycloak distribution.
  • Inventory all UMA-protected resources across realms and identify name collisions between different owners.
  • Restrict UMA resource registration to trusted client accounts where feasible until patched builds are deployed.

Patch Information

Refer to the Red Hat CVE-2026-94217 Advisory and the associated Red Hat Bug Report #2537313 for the current fix status and affected component versions. Apply updates through your standard Red Hat subscription or Keycloak upgrade channel once fixed builds are published.

Workarounds

  • Enforce a naming policy on UMA resources that includes an owner-specific prefix to prevent name collisions across users.
  • Disable UMA authorization on resource servers that do not require end-user resource sharing.
  • Limit which clients are configured as UMA resource servers and revoke uma_protection role from clients that do not need it.
bash
# Example: list UMA resources and detect duplicate names across owners
# Requires kcadm.sh authenticated against the target realm
kcadm.sh get clients/{client-uuid}/authz/resource-server/resource \
  -r {realm} --fields id,name,owner | \
  jq -r '.[] | "\(.name)\t\(.owner.name)"' | \
  sort | awk -F'\t' '{c[$1]++} END {for (n in c) if (c[n]>1) print n}'

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.