Client Policy Flaw in Keycloak Affects Security Controls
CVE-2026-18207
6.5MEDIUM
What is CVE-2026-18207?
A security issue exists in the client policy enforcement of Keycloak, where group membership is erroneously checked by name rather than by a unique identifier. This vulnerability permits attackers with client management privileges to circumvent established security policies by simply joining a group that has a name match in a different group hierarchy. Consequently, this misconfiguration enables unauthorized actions such as registering or updating clients without adhering to the necessary security hardening profiles.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.