Keycloak Client Policy Bypass via Group Name Match
CVE-2026-18207 Published on July 29, 2026
Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.
Vulnerability Analysis
CVE-2026-18207 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-18207 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18207
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.