CVE-2026-9799 - Keycloak Access Control Vulnerability in Service Virtualization (DevTest) IAM
search cancel

CVE-2026-9799 - Keycloak Access Control Vulnerability in Service Virtualization (DevTest) IAM

book

Article ID: 450768

calendar_today

Updated On:

Products

Service Virtualization

Issue/Introduction

A security flaw was identified in org.keycloak.authorization within the integrated Keycloak server used by the Identity and Access Management (IAM) component of Service Virtualization (DevTest).

An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this vulnerability by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain unauthorized access to all resources of that type within the same resource server, even without a valid ticket for those specific resources.

Conditions: This vulnerability requires the resource server to be configured in PERMISSIVE policy enforcement mode and affects typed resources with ownerManagedAccess enabled, specifically where no explicit policy protects the resource type.

Impact

The primary consequence of this vulnerability is unauthorized information disclosure or the unauthorized modification of resources.

Vulnerability Details

  • CVE-ID: CVE-2026-9799
  • CVSS Score: 4.6
  • Component: Identity and Access Management (IAM) / Keycloak
  • Alert Publication Date: June 25, 2026

Resolution

Broadcom Engineering has addressed this vulnerability by updating the integrated Keycloak libraries within the Service Virtualization IAM component.

The fix is integrated into the following release:

  • Service Virtualization (DevTest) 10.9.2

Remediation Steps

To remediate CVE-2026-9799, follow these steps:

  1. Plan Upgrade: Schedule an upgrade of your Service Virtualization (DevTest) environment to version 10.9.2 or later.
  2. Apply Update: Once the release is available, update the Identity Access Manager (IAM) component of your installation.
  3. Verification: Ensure the IAM component is running the version provided in the 10.9.2 release to confirm the vulnerability is mitigated.