ctipilot.ch

Keycloak token-exchange privilege escalation (silent subject_token removal); Keycloak 26.6.3 16-CVE release

cve · CVE-2026-9704

Coverage timeline
1
first 2026-06-07 → last 2026-06-07
Briefs
1
1 distinct
Sources cited
3
2 hosts
Sections touched
1
deep_dive
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-06-07CTI Daily Brief — 2026-06-07
    deep_diveFirst coverage. Deep dive on Keycloak 26.6.3 (16 CVEs): CVE-2026-9704 token-exchange privesc, CVE-2026-4874 OIDC SSRF, CVE-2026-8830 WebAuthn validation bypass, CVE-2026-9802 refresh-token replay, CVE-2026-9792 ROPC bypass, CVE-2026-37977 CORS; CERT-FR AVI-0669; no ITW; patch-and-harden for EU public-sector IAM.

Where this entity is cited

  • deep_dive1

Source distribution

  • keycloak.org2 (67%)
  • wid.cert-bund.de1 (33%)

Items in briefs about Keycloak token-exchange privilege escalation (silent subject_token removal); Keycloak 26.6.3 16-CVE release

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.