PatchSiren cyber security CVE debrief
CVE-2026-18570 Red Hat CVE debrief
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component of Red Hat Build of Keycloak. This issue allows a delegated user to bypass security policies by omitting the fullScopeAllowed field in a request, potentially leading to unauthorized role mappings and client creation with full scope access. Administrators and security teams managing Red Hat Build of Keycloak deployments should review and update their configurations to mitigate potential unauthorized access. This includes verifying client-policy executor configurations, monitoring client creations, and implementing compensating controls to restrict potentially unauthorized role mappings. The CVE record was published on 2026-08-02T06:16:41.230Z and has not been modified since then. Evidence from Red Hat and NVD indicates a flaw in the full-scope-disabled client-policy executor within the keycloak-services component, allowing unauthorized role mappings. Limited details available. Further review of Red Hat security advisories and Bugzilla entries related to CVE-2026-18570 is recommended to understand the full scope of the vulnerability and necessary mitigations.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-02
- Original CVE updated
- 2026-08-02
- Advisory published
- 2026-08-02
- Advisory updated
- 2026-08-02
Who should care
Administrators and security teams managing Red Hat Build of Keycloak deployments should review and update their configurations to mitigate potential unauthorized access. This includes verifying client-policy executor configurations, monitoring client creations, and implementing compensating controls to restrict potentially unauthorized role mappings. Security teams responsible for vulnerability management and incident response should also be aware of this vulnerability and plan for timely remediation or mitigation efforts.
Technical summary
The full-scope-disabled client-policy executor within the keycloak-services component of Red Hat Build of Keycloak is vulnerable to a policy bypass. By omitting the fullScopeAllowed field in a request, a delegated user can create a client with full scope access, potentially leading to unauthorized role mappings. This issue arises because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request.
Defensive priority
Medium-priority defensive review recommended due to potential unauthorized access via client creation with full scope access.
Recommended defensive actions
- Review and update client-policy executor configurations to enforce fullScopeAllowed field validation.
- Implement compensating controls to monitor and restrict client creations with potentially unauthorized role mappings.
- Verify and apply vendor remediation for the keycloak-services component.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence from Red Hat and NVD indicates a flaw in the full-scope-disabled client-policy executor within the keycloak-services component, allowing unauthorized role mappings. Limited details available. Further review of Red Hat security advisories and Bugzilla entries related to CVE-2026-18570 is recommended to understand the full scope of the vulnerability and necessary mitigations.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-02T06:16:41.230Z and has not been modified since then.