SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19608

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the group policy provider of Keycloak authorization services, affecting systems that manage access control through group-based policies. The flaw allows users from unauthorized groups to gain access to protected resources if their group names conflict with those of authorized groups, potentially leading to unauthorized access. Organizations utilizing Keycloak for access management should prioritize addressing this issue to safeguard their resources against potential exploitation.

CVE
CVE-2026-19608
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%

Original NVD Description

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-based policies using tokens that only contain group names rather than full paths. If two groups in different parts of the organization share the same name, a user in the unauthorized group can be mistaken for a member of the authorized group. This can allow a user to gain unauthorized access to protected resources they should not be able to reach.