Medium severity5.4NVD Advisory· Published Aug 2, 2026· Updated Sep 16, 2026
CVE-2026-18570
CVE-2026-18570
Description
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
4- access.redhat.com/security/cve/CVE-2026-18570nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- access.redhat.com/errata/RHSA-2026:68277nvd
- access.redhat.com/errata/RHSA-2026:68278nvd
News mentions
0No linked articles in our index yet.