PatchSiren cyber security CVE debrief
CVE-2026-18211 Red Hat CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then. The secure-client-uris client policy executor within Keycloak core services enforces security requirements on client configurations, such as requiring encrypted connections for redirect URIs. However, due to an improper check that only looks at the start of a web address rather than properly verifying the host, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections. Keycloak administrators should verify the secure-client-uris client policy executor configuration and review client configurations to ensure encrypted connections. Users relying on secure client configurations should also review their configurations and ensure that they are using encrypted connections. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then. However, defenders should note that the improper check in the secure-client-uris client policy executor could allow an attacker to intercept sensitive authentication codes over unencrypted connections. Evidence from official vulnerability databases and vendor references; limited detail on affected scope and vendor remediation.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Keycloak administrators and users relying on secure client configurations. Keycloak administrators should verify the secure-client-uris client policy executor configuration and review client configurations to ensure encrypted connections. Users relying on secure client configurations should also review their configurations and ensure that they are using encrypted connections.
Technical summary
Flaw in Keycloak core services allows bypassing security restrictions due to improper check in secure-client-uris client policy executor. The secure-client-uris client policy executor is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. However, due to the improper check, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections.
Defensive priority
Medium-priority vulnerability in Keycloak core services; verify and apply vendor remediation.
Recommended defensive actions
- Verify Keycloak core services configuration and apply vendor remediation
- Review and update client configurations to ensure encrypted connections
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from official vulnerability databases and vendor references; limited detail on affected scope and vendor remediation. Keycloak administrators should verify the secure-client-uris client policy executor configuration and review client configurations to ensure encrypted connections. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then. However, defenders should note that the improper check in the secure-client-uris client policy executor could allow an attacker to intercept sensitive authentication codes over unencrypted connections.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then.