CVE-2026-9802PoC(redhat / build_of_keycloak)

LOWCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for redhat build_of_keycloak systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful exploitation grants the attacker unauthorized access to the victim's account, potentially leading to information disclosure or privilege escalation.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
build_of_keycloak

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-24: 1PoC Mentioned / Linked · 2026-06-24: 1Exploit Tool / Code · 2026-06-24: 1Technical Details · 2026-06-24: 106-24
Signal classification1 categories
PoC
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • kmkz@kmkz_security
    PoC

    #Keycloak pwnage, all public. 1: CVE-2026-4282 forges admin tokens unauth 2: view-clients leaks every client secret, all versions, open #49220 (PoC: https://tinyurl.com/kmkz2) 3: restart revives rotated refresh tokens, CVE-2026-9802 Not every vuln has a CVE https://github.com/keycloak/keycloak/issues/

    Post summary

    The tweet lists three Keycloak CVEs, provides a PoC link for one, and summarizes the main impact of each vulnerability.

    340119516024.1K
    19.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more