ThreatCluster

Moderate Vulnerability in Keycloak Client-Policy Executor Discovered

First seen 3 Aug 2026, 14:53 UTC Nvd.Nistaccess.redhat.comcve.org 84% similarity 51

Article Content

Browse articles
ThreatCluster

A flaw has been identified in the keycloak-services component of Red Hat Build of Keycloak, specifically in the full-scope-disabled client-policy executor. This vulnerability, designated CVE-2026-18570, allows a delegated user to bypass security policies by omitting the 'fullScopeAllowed' field during client registration. As a result, clients can be created with full scope access, enabling unauthorized token acquisition. The Red Hat Product Security team has classified this vulnerability as Moderate, as exploitation requires specific privileges and policy configurations. The root cause is a failure to validate default server behavior when the required field is missing. Currently, no effective mitigation options are available that meet Red Hat's criteria for ease of use and stability. The CVE was published on August 2, 2026.

Key Points: • CVE-2026-18570 allows bypassing security policies in Keycloak. • Exploitation requires delegated client creation privileges. • No effective mitigation options currently available.

ThreatCluster AI How this analysis works

Timeline

2026-08-02
CVE-2026-18570 published
Red Hat disclosed a vulnerability in the keycloak-services component affecting client registration and configuration.
Nvd.Nist

Community

Browse all →

Tracked Entities in This Story