CVE-2026-9794
Modified Modified - Updated After Analysis
Information Disclosure in Keycloak via SAML ECP Endpoint

Publication date: 2026-05-28

Last updated on: 2026-06-10

Assigner: Red Hat, Inc.

Description
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-28
Last Modified
2026-06-10
Generated
2026-06-17
AI Q&A
2026-05-28
EPSS Evaluated
2026-06-16
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
redhat build_of_keycloak *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in Keycloak and involves the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint. A remote, unauthenticated attacker can send specially crafted SOAP requests with varying client IDs to this endpoint.

By analyzing the different faultstrings returned in the responses, the attacker can determine the protocol type used by the client. This behavior leads to an information disclosure vulnerability.

Impact Analysis

The vulnerability allows an unauthenticated remote attacker to gain information about the client's protocol type by sending crafted requests and observing the responses.

This information disclosure could potentially be used to aid further attacks or reconnaissance against the system, although it does not directly impact integrity or availability.

Detection Guidance

This vulnerability can be detected by sending specially crafted SOAP requests to the SAML ECP endpoint of the Keycloak server with varying client IDs and observing the faultstrings in the responses.

By analyzing the differences in the faultstrings returned, it is possible to determine if the system is vulnerable to information disclosure.

Specific commands are not provided in the available information.

Compliance Impact

This vulnerability leads to information disclosure by allowing an attacker to determine the client's protocol type through specially crafted SOAP requests. Such information disclosure could potentially impact compliance with standards and regulations like GDPR and HIPAA, which require protection of sensitive information and prevention of unauthorized data access.

However, the provided context and resources do not specify direct effects or assessments related to compliance with these standards.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9794. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart