Flaw in Keycloak Security Policy Enforcement by Red Hat
CVE-2026-18570

5.4MEDIUM

What is CVE-2026-18570?

A security flaw exists within the client-policy executor component of Keycloak, implemented in Red Hat's Build of Keycloak. This flaw allows a delegated user to circumvent security policies that should govern client registration and configuration. The issue arises because the executor only performs validation on the 'fullScopeAllowed' field when it is present in the request. If omitted, a client can be created with unrestricted access, gaining the ability to receive tokens that contain unauthorized role mappings. This vulnerability highlights the importance of comprehensive validation in maintaining secure client configurations.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.