SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18573

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

A vulnerability exists in the keycloak-services component of Keycloak, allowing an attacker with client management permissions to bypass authentication policies by manipulating client configurations. Specifically, an attacker can create a public client and subsequently change it to a confidential client, undermining the realm's security hardening measures. Organizations utilizing Keycloak for authentication and authorization should prioritize addressing this issue to prevent unauthorized access and ensure compliance with security protocols.

CVE
CVE-2026-18573
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.

Related CVEs

Other vulnerabilities affecting the same vendor(s)