Client Policy Flaw in Keycloak Affects Security Controls
CVE-2026-18207

6.5MEDIUM

What is CVE-2026-18207?

A security issue exists in the client policy enforcement of Keycloak, where group membership is erroneously checked by name rather than by a unique identifier. This vulnerability permits attackers with client management privileges to circumvent established security policies by simply joining a group that has a name match in a different group hierarchy. Consequently, this misconfiguration enables unauthorized actions such as registering or updating clients without adhering to the necessary security hardening profiles.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.