SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18570

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

A vulnerability exists in the keycloak-services component of Red Hat Build of Keycloak, where the client-policy executor fails to validate the fullScopeAllowed field unless explicitly included in a request. This oversight allows delegated users to create clients with full scope access, potentially enabling unauthorized token acquisition with elevated role mappings. Organizations using Red Hat Build of Keycloak should prioritize addressing this issue to prevent unauthorized access and maintain security integrity.

CVE
CVE-2026-18570
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.

Related CVEs

Other vulnerabilities affecting the same vendor(s)