BIT-keycloak-2026-18570

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-18570.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-keycloak-2026-18570
Aliases
  • CVE-2026-18570
Published
2026-08-31T14:37:18Z
Modified
2026-09-17T14:45:10Z
Summary
Keycloak-services: keycloak-services: full-scope-disabled client policy validation bypass via omitted fullscopeallowed
Details

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.

Database specific
{
    "cpes": [
        "cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:keycloak:keycloak:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / keycloak

Package

Name
keycloak
Purl
pkg:bitnami/keycloak

Severity

  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.7.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/keycloak/BIT-keycloak-2026-18570.json"