CVE-2026-8830: Keycloak: org.keycloak/keycloak-services: keycloak: policy bypass during webauthn credential registration via client-side javascript manipulation

Published May 18, 2026
·
Updated

A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that the newly created credential's parameters, such as public key algorithms, match the realm's configured WebAuthn policies. This could lead to the creation of credentials that do not adhere to administrative security requirements, potentially weakening the overall security posture of the system by allowing non-compliant authentication methods.

Other sources

During WebAuthn credential registration, the server-side processAction() fails to validate that the newly created credential's parameters (such as public key algorithms) match the realm's configured WebAuthn policies. This allows a user to bypass administrative restrictions (e.g., algorithm requirements, user verification, or resident key configuration) by modifying client-side JavaScript during the registration process.

Red Hat

Affected Software

2 affected components
maven/org.keycloak/keycloak-services
redhat Build Of Keycloak

Event History

May 18, 2026
Data Sourced
via Red Hat·01:09 PM
DescriptionSeverityAffected Software
May 19, 2026
CVE Published
via MITRE·06:04 AM
Data Sourced
via MITRE·06:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Apr 28, 58520
Event
via FIRST·03:47 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-8830?

The severity of CVE-2026-8830 is medium with a CVSS score of 4.3.

2

How does CVE-2026-8830 affect Keycloak users?

CVE-2026-8830 allows authenticated users to bypass WebAuthn policies during credential registration by manipulating client-side JavaScript.

3

What type of vulnerability is CVE-2026-8830?

CVE-2026-8830 is a policy bypass vulnerability related to WebAuthn credential registration.

4

How can I mitigate CVE-2026-8830?

To mitigate CVE-2026-8830, ensure that server-side validation is implemented for the parameters of newly created WebAuthn credentials.

5

What software versions are affected by CVE-2026-8830?

CVE-2026-8830 affects the org.keycloak/keycloak-services component of Keycloak.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203