Path Matching Flaw in Keycloak's Authorization Services Exposes Restricted Areas
CVE-2026-15573

8.1HIGH

What is CVE-2026-15573?

A vulnerability exists in Keycloak's Authorization Services due to improper normalization of URIs in the PathMatcher component. This security oversight allows attackers to manipulate request paths by appending additional characters, such as trailing slashes or matrix parameters, leading to the potential application of less stringent security policies. Consequently, authenticated users may gain unauthorized access to administrative or restricted areas of the system, undermining the intended security measures.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Sanil Dulal for reporting this issue.
.