Access Management Flaw in Keycloak Admin REST API
CVE-2026-94215

5.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
21 September 2026

What is CVE-2026-94215?

A vulnerability exists in the Admin REST API of Keycloak, where a flaw allows an unauthorized administrator to access and modify sensitive client configurations across different realms. This occurs due to the use of a per-request in-memory cache, which incorrectly resolves clients without verifying their realm association. Consequently, this could enable potential attackers to compromise client credentials or redirect administrative logins to malicious sites, emphasizing the need for stringent access control and verification mechanisms.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.