SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18201

MEDIUM · CVSS 5.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A vulnerability exists in Keycloak's administrative API, allowing an administrator with the ability to manage identity providers to link a new provider to an organization without the necessary permissions. This could enable unauthorized access and manipulation of user login methods for specific organizations, potentially compromising user authentication processes. Organizations using Keycloak should prioritize addressing this issue to safeguard their identity management systems.

CVE
CVE-2026-18201
Severity
MEDIUM
CVSS
5.5
EPSS
0.22%

Original NVD Description

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

Related CVEs

Other vulnerabilities affecting the same vendor(s)