Authentication Flaw in Keycloak Services Affects Client Security Policies
CVE-2026-18573
6.5MEDIUM
What is CVE-2026-18573?
A vulnerability exists in the keycloak-services component of Keycloak that compromises authentication and authorization processes. The flaw arises when realm administrators attempt to enforce client policies on confidential clients. An attacker with client management permissions could exploit this flaw by first creating a public client and then changing it to a confidential client with less stringent authentication measures. This manipulation leads to the possibility of non-compliant clients remaining operational, undermining the security hardening measures intended for the realm.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.