Junglewise Threat Intelligence

CVE-2026-18207: Keycloak improper authorization in client policy enforcement

CVE-2026-18207 · Severity: medium · CVSS 6.5 · Published 2026-07-29

Technologies: Red Hat build of Keycloak, Red Hat build of Keycloak. Vendors: Red Hat.

Executive brief

A security flaw was found in Keycloak, an open-source identity and access management solution. The system incorrectly verifies user group memberships by name rather than a unique ID, which could allow an authorized user with client management permissions to bypass security policies. This could result in the unauthorized registration or modification of applications without following the organization's required security standards.

Technical details

An improper authorization vulnerability (CWE-285) exists in Keycloak's client policy enforcement mechanism. The root cause is the system's reliance on group names rather than unique identifiers when validating group membership for policy enforcement. A remote attacker with low-level client management privileges can exploit this by joining or creating a group with a name that matches a privileged group in a different branch of the group hierarchy. This bypass allows the attacker to register or update clients while circumventing mandatory security hardening profiles. The vulnerability is tracked as CVE-2026-18207 and affects the Red Hat Build of Keycloak.

Affected products

  • Red Hat Red Hat Build of Keycloak All versions

Timeline

  • 2026-07-29: disclosed: Initial publication of the CVE record.
  • 2026-07-29: advisory: Advisory published by Red Hat.

References

Related threats