A substring match that turns Keycloak's policy enforcer off

CVE-2026-9800 — Keycloak’s policy enforcer used a substring match to detect its own access-denied page, so any authenticated user could append that path and skip every authorization check. The first package I ever audited, and a .contains() that lets everyone in.

June 29, 2026 · 6 min · 1171 words · Bas Levering