CVE-2026-9086 is a cross-site scripting vulnerability in Keycloak client redirect URI validation. An attacker holding administrative client-management privileges, or access to client-registration endpoints, can register a malicious client using a specially crafted redirect URI with a case-insensitive javascript: or data: scheme. When a victim follows a crafted link, including during logout or in the Admin Console, attacker-controlled code executes in the Keycloak origin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
manage-client privileges and access to client registration endpoints to only fully trusted administrators and automation. Review existing client registrations for unsafe redirect URIs using non-HTTP(S) schemes or mixed-case scheme variants. Where possible, disable or tightly control dynamic client registration, monitor administrative changes to client configuration, and reduce exposure of administrative interfaces to untrusted users.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, self-contained PoC for CVE-2026-9086 affecting Keycloak client URI validation. It contains two README files (English/Japanese), a docker-compose.yml for spinning up vulnerable Keycloak 26.6.3 and fixed Keycloak 26.6.4 instances, and a single Python script (exploit.py) that performs the actual test. The exploit capability is limited to authenticated validation-bypass testing through the Keycloak Admin REST API. The script logs in with the resource owner password flow against the realm token endpoint using client_id 'admin-cli', creates a randomized client object with redirectUris containing either a mixed-case 'jaVaSCript:' URI or a mixed-case 'DaTa:' URI, and evaluates the server response. If the target returns HTTP 201, it follows the Location header to retrieve the created client and confirms the malicious URI was stored. If the target is fixed, it expects HTTP 400. This makes it an authenticated PoC that demonstrates exploitability without delivering a browser-stage payload. Repository structure and purpose: - README.en.md / README.md: explain the vulnerability, affected versions, usage, and expected results. - docker-compose.yml: launches two local Keycloak containers on ports 8180 and 8181 for vulnerable/fixed comparison. - exploit.py: main entry point; handles authentication, client creation, verification, and result reporting. Notable implementation details: - Uses only Python standard library modules: argparse, json, urllib, uuid, sys. - No framework dependency and no persistence, shell, or post-exploitation behavior. - The PoC explicitly does not open the stored URI or execute JavaScript; it only proves server-side acceptance/storage of a dangerous redirect URI. Overall, this is a legitimate authenticated web exploit PoC for demonstrating a Keycloak XSS-related URI scheme validation bypass, primarily useful for verification and regression testing rather than weaponized exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.