CyberRota
← Ana sayfaya dön

CVE-2026-18203

MEDIUM · CVSS 6.5

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-31T08:16:27.010 · Çekilme zamanı: 2026-07-31T12:07:48.553799+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-18203
Severity
MEDIUM
CVSS
6.5
EPSS
Yok

Orijinal NVD Açıklaması

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.