Input validation error in Keycloak - CVE-2026-16102

 

Input validation error in Keycloak - CVE-2026-16102

Published: August 6, 2026


Vulnerability identifier: #VU141168
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16102
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to forge administrative roles in their access token.

The vulnerability exists due to improper input validation in the default Dynamic Client Registration policy when processing User Property mappers with claim paths targeting sensitive internal claim locations. A remote user can use a limited Initial Access Token and write values to sensitive internal claim locations to forge administrative roles in their access token.

This can lead to takeover of other clients, theft of confidential secrets, and potential full administrative control over the realm.


Affected software

Keycloak

How to mitigate CVE-2026-16102

Install security update from vendor's website.

Keycloak - addressed in versions 26.4.14, 26.6.5, 26.7.1

External References

Related Security Bulletins