Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-18207

Опубликовано: 29 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

EPSS

Процентиль: 24%
0.00312
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.5
redhat
20 дней назад

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

CVSS3: 6.5
debian
19 дней назад

A flaw was found in the client policy enforcement mechanism of Keycloa ...

CVSS3: 6.5
github
19 дней назад

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

EPSS

Процентиль: 24%
0.00312
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285