Wildcard Domain Bypass in Keycloak Identity and Access Management Services
CVE-2026-18206

3.7LOW

What is CVE-2026-18206?

A flaw exists in the keycloak-services component of Keycloak, impacting its ability to effectively restrict client registration and updates when using wildcard domains. Specifically, the issue arises when realm administrators employ wildcard patterns (e.g., *.example.com) for domain restrictions. Due to inadequate validation mechanisms, the system erroneously allows any hostname that concludes with the designated domain suffix, despite not being an approved subdomain. This vulnerability could be exploited by attackers who manipulate their DNS settings, facilitating unauthorized modifications to client entries, which poses significant security risks for organizations utilizing Keycloak for identity and access management.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.