Input validation error in Keycloak - CVE-2026-16102
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to forge administrative roles in their access token.
The vulnerability exists due to improper input validation in the default Dynamic Client Registration policy when processing User Property mappers with claim paths targeting sensitive internal claim locations. A remote user can use a limited Initial Access Token and write values to sensitive internal claim locations to forge administrative roles in their access token.
This can lead to takeover of other clients, theft of confidential secrets, and potential full administrative control over the realm.