Type Confusion in Keycloak - CVE-2026-15572
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to gain full administrative access to the Keycloak realm.
The vulnerability exists due to access of resource using incompatible type in the Dynamic Client Registration \"Allowed Protocol Mapper Types\" policy when processing client update requests. A remote user can register an allowed mapper type with a malicious configuration and then swap it to a restricted high-privilege mapper type to gain full administrative access to the Keycloak realm.
Exploitation requires client registration privileges.