A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.
History

Thu, 28 May 2026 04:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.
Title Keycloak: keycloak: information disclosure via saml ecp endpoint
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-209
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-05-28T03:44:20.414Z

Reserved: 2026-05-28T03:15:11.408Z

Link: CVE-2026-9794

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-28T05:16:40.847

Modified: 2026-05-28T05:16:40.847

Link: CVE-2026-9794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T06:15:10Z