CyberRota
← Ana sayfaya dön

CVE-2026-18206

LOW · CVSS 3.7

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-31T08:16:27.177 · Çekilme zamanı: 2026-07-31T12:07:48.619880+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-18206
Severity
LOW
CVSS
3.7
EPSS
Yok

Orijinal NVD Açıklaması

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.example.com) to restrict which hosts can register or update clients. Due to improper validation, the system accepts any hostname that ends with the specified domain suffix, even if it is not a legitimate subdomain. An attacker who can control the reverse DNS of their connection can bypass these host-based restrictions, potentially allowing unauthorized client modifications.