CVE-CVE-2026-9086
Severity
HIGH
CVSS Score
7.3
Description
A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoints, could bypass client Uniform Resource Identifier (URI) validation. This is achieved by registering a malicious client with a specially crafted redirect URI using a case-insensitive `javascript:` or `data:` scheme. This Cross-Site Scripting (XSS) vulnerability allows for arbitrary code execution in the Keycloak origin when a ...
PoCs for CVE-CVE-2026-9086
CVE-2026-9086-poc
General
Python
0
Saku0512
2026-08-10