AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15573

HIGH · CVSS 8.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability in Keycloak's Authorization Services allows attackers to exploit improper URI normalization in the PathMatcher component. By manipulating request paths with additional characters, an authenticated user can bypass security policies, potentially gaining unauthorized access to administrative or restricted areas. Organizations using Keycloak should prioritize addressing this issue to safeguard sensitive data and maintain proper access controls.

CVE
CVE-2026-15573
Severity
HIGH
CVSS
8.1
EPSS
0.29%

Original NVD Description

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.

Related CVEs

Other vulnerabilities affecting the same vendor(s)