SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18207

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A vulnerability exists in Keycloak's client policy enforcement mechanism, where group membership is verified by name rather than a unique identifier. This flaw allows an attacker with client management privileges to bypass security policies by joining a group with a matching name elsewhere in the hierarchy, potentially enabling unauthorized registration or updates of clients. Organizations using Keycloak, particularly those with client management capabilities, should prioritize addressing this issue to maintain security compliance.

CVE
CVE-2026-18207
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%

Original NVD Description

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

Related CVEs

Other vulnerabilities affecting the same vendor(s)