Path Matching Flaw in Keycloak's Authorization Services Exposes Restricted Areas
CVE-2026-15573
8.1HIGH
What is CVE-2026-15573?
A vulnerability exists in Keycloak's Authorization Services due to improper normalization of URIs in the PathMatcher component. This security oversight allows attackers to manipulate request paths by appending additional characters, such as trailing slashes or matrix parameters, leading to the potential application of less stringent security policies. Consequently, authenticated users may gain unauthorized access to administrative or restricted areas of the system, undermining the intended security measures.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Sanil Dulal for reporting this issue.