CVE-2026-95503
Received Received - Intake

Kerberos Authentication Bypass in Keycloak

Vulnerability report for CVE-2026-95503, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: redhat-SADP

Description

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without SPNEGO, the system fails to verify the identity of the Key Distribution Center (KDC) by requesting a server ticket. This allows an attacker on the same network to spoof the KDC and bypass the authentication process, potentially gaining unauthorized access to user accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
keycloak keycloak *
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's Kerberos federation provider. When Kerberos password authentication is used without SPNEGO, Keycloak fails to verify the Key Distribution Center (KDC) by not requesting a server ticket. This allows an attacker on the same network to spoof the KDC and bypass authentication entirely, potentially gaining unauthorized access to user accounts.

Detection Guidance

Monitor network traffic for unauthorized Kerberos responses or spoofed KDC communications. Check Keycloak logs for failed authentication attempts or unexpected Kerberos ticket requests. Use tools like Wireshark to inspect Kerberos traffic for anomalies in server ticket requests.

Impact Analysis

An attacker could impersonate any user, bypass authentication, and gain unauthorized access to sensitive data or administrative functions. The attack requires being on the same network and can be executed without needing special privileges or user interaction.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. It undermines authentication controls, potentially resulting in non-compliance with data protection regulations.

Mitigation Strategies

Disable Kerberos password authentication without SPNEGO in Keycloak. Ensure SPNEGO is enabled for Kerberos authentication. Monitor network for ARP, DNS, or DHCP spoofing attempts. Apply patches or updates from Keycloak once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95503. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart