漏洞总结:CVE-2026-8830 漏洞概述 漏洞编号:CVE-2026-8830 组件:keycloak/keycloak-services 类型:WebAuthn 凭证注册过程中的客户端 JavaScript 操纵导致策略绕过 严重程度:medium 优先级:medium 状态:NEW 影响范围 受影响产品:Security Response 操作系统:Linux 硬件架构:x86_64 CC 列表:11 users 修复方案 修复版本:未指定 克隆状态:Clone Of 最后关闭:未关闭 embargoed:是 漏洞描述 在 WebAuthn 凭证注册过程中,服务器端 方法未能验证新创建的凭证参数(如公钥算法)是否与 realm 配置的 WebAuthn 策略匹配。这允许用户通过修改客户端 JavaScript 来绕过管理员限制(例如算法要求、用户验证或 resident key 配置)。 附件 OSIDB Botpost:2026-05-18 13:09:22 UTC - 描述:During WebAuthn credential registration, the server-side processAction() fails to validate that the newly created credential's parameters (such as public key algorithms) match the realm's configured WebAuthn policies. This allows a user to bypass administrative restrictions (e.g., algorithm requirements, user verification, or resident key configuration) by modifying client-side JavaScript during the registration process.