CVE-2026-9705
🔶 mediumSummary
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled. This bypasses security controls, allowing the attacker to reset the client's secret and potentially regain privileged API access. The primary impact includes unauthorized information disclosure and potential integrity compromise.
CVSS Score
6.5
Medium
EPSS Score
0.3
Exploit Probability
Published Date
2026-06-25
First Seen: 2026-06-26
📊 Relative Risk Intelligence
This CVE is Lower Risk - more severe than 47.6% of all 338,292 vulnerabilities in our database.
#177,181
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jun 29, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
Red Hat would like to thank Qiulin Deng for reporting this issue.
SSVC data provided by
CISA
Last Modified
2026-07-01
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE IDs (Weakness Types)