PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18211 Red Hat CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then. The secure-client-uris client policy executor within Keycloak core services enforces security requirements on client configurations, such as requiring encrypted connections for redirect URIs. However, due to an improper check that only looks at the start of a web address rather than properly verifying the host, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections. Keycloak administrators should verify the secure-client-uris client policy executor configuration and review client configurations to ensure encrypted connections. Users relying on secure client configurations should also review their configurations and ensure that they are using encrypted connections. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then. However, defenders should note that the improper check in the secure-client-uris client policy executor could allow an attacker to intercept sensitive authentication codes over unencrypted connections. Evidence from official vulnerability databases and vendor references; limited detail on affected scope and vendor remediation.

Vendor
Red Hat
Product
Red Hat Build of Keycloak
CVSS
MEDIUM 4.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-31
Original CVE updated
2026-07-31
Advisory published
2026-07-31
Advisory updated
2026-07-31

Who should care

Keycloak administrators and users relying on secure client configurations. Keycloak administrators should verify the secure-client-uris client policy executor configuration and review client configurations to ensure encrypted connections. Users relying on secure client configurations should also review their configurations and ensure that they are using encrypted connections.

Technical summary

Flaw in Keycloak core services allows bypassing security restrictions due to improper check in secure-client-uris client policy executor. The secure-client-uris client policy executor is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. However, due to the improper check, an attacker can bypass these security restrictions by using a specially crafted domain name. This could allow an attacker to intercept sensitive authentication codes over unencrypted connections.

Defensive priority

Medium-priority vulnerability in Keycloak core services; verify and apply vendor remediation.

Recommended defensive actions

  • Verify Keycloak core services configuration and apply vendor remediation
  • Review and update client configurations to ensure encrypted connections
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence from official vulnerability databases and vendor references; limited detail on affected scope and vendor remediation. Keycloak administrators should verify the secure-client-uris client policy executor configuration and review client configurations to ensure encrypted connections. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then. However, defenders should note that the improper check in the secure-client-uris client policy executor could allow an attacker to intercept sensitive authentication codes over unencrypted connections.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:27.610Z and has not been modified since then.