CVE-2026-18207

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-07-29 10:16

Updated : 2026-08-11 01:35


NVD link : CVE-2026-18207

Mitre link : CVE-2026-18207

CVE.ORG link : CVE-2026-18207


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-285

Improper Authorization