Flaw in Keycloak Security Policy Enforcement by Red Hat
CVE-2026-18570
5.4MEDIUM
What is CVE-2026-18570?
A security flaw exists within the client-policy executor component of Keycloak, implemented in Red Hat's Build of Keycloak. This flaw allows a delegated user to circumvent security policies that should govern client registration and configuration. The issue arises because the executor only performs validation on the 'fullScopeAllowed' field when it is present in the request. If omitted, a client can be created with unrestricted access, gaining the ability to receive tokens that contain unauthorized role mappings. This vulnerability highlights the importance of comprehensive validation in maintaining secure client configurations.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.