Vulnerability Details CVE-2026-18207
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 21.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-18207
-
cpe:2.3:a:redhat:build_of_keycloak:-