SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18203

MEDIUM · CVSS 6.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

A vulnerability in the group policy evaluation logic of Keycloak allows users to exploit a flawed prefix check for group membership, potentially granting them unauthorized access to administrative functions or protected resources. This issue affects unspecified products utilizing Keycloak for identity and access management. Organizations using Keycloak should prioritize addressing this vulnerability to mitigate the risk of unauthorized access.

CVE
CVE-2026-18203
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%

Original NVD Description

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.

Related CVEs

Other vulnerabilities affecting the same vendor(s)