A substring match that turns Keycloak's policy enforcer off
CVE-2026-9800 — Keycloak’s policy enforcer used a substring match to detect its own access-denied page, so any authenticated user could append that path and skip every authorization check. The first package I ever audited, and a .contains() that lets everyone in.