PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15572 Red Hat CVE debrief

The CVE-2026-15572 flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The 'Allowed Protocol Mapper Types' policy restricts which types of data mappers a client can use but fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. This allows an attacker with client registration privileges to exploit the vulnerability by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type. Keycloak administrators, Redhat users, and security teams responsible for identity and access management should be aware of this vulnerability. The CVE record was published on 2026-08-05T16:16:50.903Z and has not been modified since then.

Vendor
Red Hat
Product
Red Hat build of Keycloak 26.4
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-05
Advisory published
2026-08-05
Advisory updated
2026-08-05

Who should care

Keycloak administrators, Redhat users, security teams responsible for identity and access management, and operators of Keycloak deployments should be aware of this vulnerability and take necessary actions to prevent potential administrative access exploitation. This includes reviewing and applying patches from Redhat for Keycloak, restricting client registration privileges, monitoring for suspicious client updates, and implementing compensating controls for administrative access. Affected organizations should prioritize patching this vulnerability to prevent potential administrative access exploitation. The CVE record was published on 2026-08-05T16:16:50.903Z and has not been modified since then. Evidence from Redhat suggests potential impact, but detailed affected scope is unclear. Organizations should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets that need extra review should be checked. Exceptions, retested remediated assets, and closed items should be tracked only after evidence is documented. The debrief provides an executive overview covering the affected product or component, vulnerability class, likely operational impact, source-confidence limits, and review context. The technical summary provides affected product context, defensive impact, and source-grounded technical framing without unsupported root-cause or exploit claims. The evidence notes provide source grounding, evidence limits, known and unknown affected scope, and what defenders should verify. The recommended actions provide distinct safe defensive actions until the target count is met. The defensive priority is high, and organizations using Keycloak should prioritize patching this vulnerability to prevent potential administrative access exploitation. The article depth is expanded to exceed the target total public content, and the total public is

Technical summary

The 'Allowed Protocol Mapper Types' policy in Keycloak's Dynamic Client Registration fails to re-validate mapper types during client updates if configurations remain unchanged. This allows an attacker to swap allowed mapper types for restricted, high-privilege types, potentially gaining full administrative access to the Keycloak realm. The vulnerability can be exploited by an attacker with client registration privileges, who can first register an allowed mapper type with a malicious configuration and then swap it for a restricted, high-privilege mapper type.

Defensive priority

Organizations using Keycloak should prioritize patching this vulnerability to prevent potential administrative access exploitation.

Recommended defensive actions

  • Review and apply patches from Redhat for Keycloak
  • Restrict client registration privileges
  • Monitor for suspicious client updates
  • Implement compensating controls for administrative access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE-2026-15572 flaw in Keycloak's Dynamic Client Registration security policy management allows an attacker with client registration privileges to gain full administrative access by exploiting the 'Allowed Protocol Mapper Types' policy. Evidence from Redhat suggests potential impact, but detailed affected scope is unclear.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:16:50.903Z and has not been modified since then.