PatchSiren cyber security CVE debrief
CVE-2026-18573 Red Hat CVE debrief
A flaw in the keycloak-services component of Keycloak allows an attacker with client management permissions to bypass security policies by creating a public client and updating it to a confidential client with weaker authentication. This issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker can persist clients that do not comply with the intended security hardening of the realm. The CVE record was published on 2026-08-02T06:16:42.673Z and has not been modified since then. Keycloak administrators and users with client management permissions should review and update their configurations to prevent potential authentication bypass. This includes verifying client management permissions, update operations, and monitoring for public client creations and updates to confidential clients.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-02
- Original CVE updated
- 2026-08-02
- Advisory published
- 2026-08-02
- Advisory updated
- 2026-08-02
Who should care
Keycloak administrators and users with client management permissions should review and update their configurations to prevent potential authentication bypass. This includes verifying client management permissions, update operations, and monitoring for public client creations and updates to confidential clients. Additionally, security teams and vulnerability management teams should be aware of the potential impact on their systems and take necessary precautions to prevent exploitation. Affected operators and platform teams should also review the configurations and take necessary actions to prevent authentication bypass. This may involve reviewing client policies and authentication requirements for confidential clients in Keycloak and verifying client management permissions and update operations. Monitoring for public client creations and updates to confidential clients is also necessary to prevent potential authentication bypass. Asset inventory and security teams should also review the configurations and take necessary actions to prevent exploitation. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Exceptions, retest remediated assets, and close the item only after evidence is documented. This requires coordination between different teams, including security, operations, and development teams. The goal is to prevent potential authentication bypass and ensure the security of the system. This requires a thorough review of the configurations and taking necessary precautions to prevent exploitation. The review should include verifying client management permissions, update operations, and monitoring for public client creations and updates to confidential clients. The review should also include checking relevant monitoring, detection, and logs for exposed assets that need extra review. Tracking exceptions, retest remediated assets, and close the item only after evidence is documented is also necessary. This will help to ensure the security of the system and prevent potential authentication bypass. The security of the system is a shared responsibility that requires coordination between different teams. The goal,
Technical summary
A flaw in the keycloak-services component of Keycloak allows an attacker with client management permissions to bypass security policies by creating a public client and updating it to a confidential client with weaker authentication. This issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker can persist clients that do not comply with the intended security hardening of the realm. Keycloak administrators should review and update their configurations to prevent potential authentication bypass.
Defensive priority
Medium-priority defensive review recommended due to potential authentication bypass in Keycloak.
Recommended defensive actions
- Review client policies and authentication requirements for confidential clients in Keycloak
- Verify client management permissions and update operations
- Monitor for public client creations and updates to confidential clients
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The evidence from Redhat indicates a flaw in the keycloak-services component of Keycloak, allowing an attacker with client management permissions to bypass security policies. Further verification is needed to confirm affected scope and vendor remediation. Additional review of client configurations and authentication requirements is necessary to prevent potential authentication bypass. This may involve verifying client management permissions, update operations, and monitoring for public client creations and updates to confidential clients.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-02T06:16:42.673Z and has not been modified since then.