CVE-2026-9705: Keycloak Client Registration Service Vulnerability in Service Virtualization (DevTest) IAM
search cancel

CVE-2026-9705: Keycloak Client Registration Service Vulnerability in Service Virtualization (DevTest) IAM

book

Article ID: 451034

calendar_today

Updated On:

Products

Service Virtualization

Issue/Introduction

Vulnerability Details

  • CVE-ID: CVE-2026-9705
  • CVSS Score: 6.5
  • Description: A security flaw was identified in Keycloak's client registration service. A remote attacker who possesses a previously issued Registration Access Token (RAT) could exploit this vulnerability to re-enable a client that an administrator had explicitly disabled.
  • Impact: This bypass allows an attacker to reset the client's secret and potentially regain privileged API access, leading to unauthorized information disclosure and compromise of system integrity.

Environment

Product: Service Virtualization (DevTest) 

Component: Identity and Access Management (IAM) / Keycloak 

Severity: Medium (CVSS 6.5)

Resolution

Broadcom Engineering has addressed this vulnerability by updating the integrated Keycloak libraries within the Service Virtualization IAM component. The fix is scheduled to be included in the following releases:

  • Service Virtualization (DevTest) 10.9.1.2
  • Service Virtualization (DevTest) 10.9.2 (Tentatively expected Sep. 2026)

Remediation Steps

  1. Identify Current Version: Check your current installation of Service Virtualization (DevTest) to determine if you are running a version prior to 10.9.1.2.
  2. Plan Upgrade: Schedule an upgrade of your DevTest environment to version 10.9.1.2 or 10.9.2 once they become available.
  3. Apply Update: Update the Identity Access Manager (IAM) component specifically to ensure the library fixes are applied.
  4. Verification: After upgrading, verify that the IAM component version matches or exceeds the versions listed above to confirm the vulnerability is mitigated.