Vulnerability Details CVE-2026-18203
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly uses a simple text-based prefix check to verify group membership. This allows a user who belongs to a different group with a similar starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.9%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-18203
-
cpe:2.3:a:redhat:build_of_keycloak:-