Moderate Vulnerability in Keycloak Client-Policy Executor Discovered
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A flaw has been identified in the keycloak-services component of Red Hat Build of Keycloak, specifically in the full-scope-disabled client-policy executor. This vulnerability, designated CVE-2026-18570, allows a delegated user to bypass security policies by omitting the 'fullScopeAllowed' field during client registration. As a result, clients can be created with full scope access, enabling unauthorized token acquisition. The Red Hat Product Security team has classified this vulnerability as Moderate, as exploitation requires specific privileges and policy configurations. The root cause is a failure to validate default server behavior when the required field is missing. Currently, no effective mitigation options are available that meet Red Hat's criteria for ease of use and stability. The CVE was published on August 2, 2026.
Key Points: • CVE-2026-18570 allows bypassing security policies in Keycloak. • Exploitation requires delegated client creation privileges. • No effective mitigation options currently available.