CVE-2026-18206

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-07-31 08:16

Updated : 2026-08-07 14:54


NVD link : CVE-2026-18206

Mitre link : CVE-2026-18206

CVE.ORG link : CVE-2026-18206


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-20

Improper Input Validation