漏洞概述 漏洞名称: CVE-2026-9794 漏洞描述: 在Keycloak中发现了一个漏洞,远程未认证的攻击者可以通过向SAML ECP(Security Assertion Markup Language Enhanced Client or Proxy)端点发送特制的SOAP请求来利用此漏洞。通过观察响应中的不同faultstrings,攻击者可以确定客户端的协议类型,从而导致信息泄露。 影响范围 产品: Security Response 组件: vulnerability 版本: unspecified 硬件: All 操作系统: Linux 优先级: medium 严重程度: medium 修复方案 状态: NEW CC列表: 10 users 环境: unspecified 最后关闭: unspecified 已屏蔽: unspecified 附加信息 报告时间: 2026-05-28 03:17 UTC by OSIDB Bzimport 修改时间: 2026-05-28 03:41 UTC 目标里程碑: unspecified 分配给: Product Security DevOps Team QA联系人: unspecified 文档联系人: unspecified URL: unspecified 白板: unspecified 依赖项: unspecified 阻塞项: unspecified 备注 需要登录才能评论或对此漏洞进行更改。 附件 附件名称: (Terms of Use) 描述: 无具体描述 漏洞详情 漏洞描述: A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the responses, the attacker can determine the client's protocol type, leading to information disclosure. 代码块 页面中未包含POC代码或利用代码。