CVE-2026-97176: Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator

Published Sep 24, 2026
·
Updated

A flaw was found in Keycloak's Level of Authentication (LoA) enforcement within the ConditionalLoaAuthenticator component. When a client requests a specific acr level as essential:true via the OIDC claims request parameter and an existing SSO session is present, Keycloak can silently issue a token asserting a lower acr level than required without triggering the mandatory forced-level failure. The vulnerability exists because when the browser flow re-evaluates an existing session via the Cookie authenticator, LoA-gated Conditional sub-flows may be disabled (e.g., if the user lacks the required credentials for the higher level). In this scenario, the ConditionalLoaAuthenticator fails to register its top-flow-success callback. Consequently, the onTopFlowSuccess() method is never executed, and the mandatory forced-level check is bypassed. An authenticated attacker with a valid low-level session can exploit this to obtain tokens for clients requiring higher authentication levels (essential:true) without providing the necessary additional factors. This results in an authentication level bypass for relying parties that trust the acr claim to guarantee the level was verified during the current authentication.

Other sources

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims.

MITRE

Affected Software

1 affected component
Red Hat Keycloak

Event History

Sep 24, 2026
Data Sourced
via Red Hat·05:35 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·05:47 AM
Data Sourced
via MITRE·05:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this authentication-level bypass?

Relying parties are exposed if they request a specific ACR level as essential:true and trust the acr claim to confirm that the required authentication level was actually verified. The issue affects flows involving an existing SSO session where LoA-gated conditional sub-flows can be disabled.

2

What does an attacker need to exploit the issue?

The attacker must already be authenticated with a valid session at a lower authentication level. They can then request tokens for a client requiring a higher essential ACR level without completing the required additional factors.

3

How can defenders identify potentially affected configurations?

Review clients that use the OIDC claims request parameter to require an ACR level with essential:true. Prioritize configurations where browser cookie-based SSO session reuse occurs and higher-LoA conditional sub-flows may be disabled because users lack the credentials required for that level.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203