Comparison Using Wrong Factors Affecting candlepin-selinux package, versions *


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.31% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL7-CANDLEPINSELINUX-17795915
  • published2 Jul 2026
  • disclosed19 May 2026

Introduced: 19 May 2026

CVE-2026-9800  (opens in a new tab)
CWE-1025  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:7 candlepin-selinux.

NVD Description

Note: Versions mentioned in the description apply only to the upstream candlepin-selinux package and not the candlepin-selinux package as distributed by RHEL. See How to fix? for RHEL:7 relevant fixed versions and status.

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.

CVSS Base Scores

version 3.1