Wildcard Domain Bypass in Keycloak Identity and Access Management Services
CVE-2026-18206
What is CVE-2026-18206?
A flaw exists in the keycloak-services component of Keycloak, impacting its ability to effectively restrict client registration and updates when using wildcard domains. Specifically, the issue arises when realm administrators employ wildcard patterns (e.g., *.example.com) for domain restrictions. Due to inadequate validation mechanisms, the system erroneously allows any hostname that concludes with the designated domain suffix, despite not being an approved subdomain. This vulnerability could be exploited by attackers who manipulate their DNS settings, facilitating unauthorized modifications to client entries, which poses significant security risks for organizations utilizing Keycloak for identity and access management.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved