Red HatCVE-2026-16093
Red Hat Data Grid 8: untrusted input in a security decision
Medium5.4CVE-2026-16093 · Published Jul 17, 2026 · updated Sep 16, 2026
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Data Grid 8 Product | all versions | No fix yet |
| Red Hat JBoss Enterprise Application Platform Expansion Pack Product | all versions | No fix yet |
| Red Hat Single Sign-On 7 Product | all versions | No fix yet |
| Red Hat build of Keycloak 26.6.7 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-807
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | Red Hat xdgmime: heap buffer overflow | High7.1 | No fix yet |
| Jul 17 | Red Hat keycloak-services: attacker could obtain access | Medium4.3 | No fix yet |
| Jul 17 | Red Hat Data Grid 8: weakly protected credentials | Medium4.3 | No fix yet |
| Jul 17 | Red Hat admin REST API of Keycloak: missing authorization | Medium4.9 | No fix yet |
| Jul 17 | Red Hat default-groups REST endpoint: information disclosure | Medium4.3 | No fix yet |
| Jul 17 | Red Hat keycloak-services: session fixation | Medium5.4 | No fix yet |