Type Confusion in Keycloak - CVE-2026-15572

 

Type Confusion in Keycloak - CVE-2026-15572

Published: August 6, 2026


Vulnerability identifier: #VU141173
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-15572
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain full administrative access to the Keycloak realm.

The vulnerability exists due to access of resource using incompatible type in the Dynamic Client Registration \"Allowed Protocol Mapper Types\" policy when processing client update requests. A remote user can register an allowed mapper type with a malicious configuration and then swap it to a restricted high-privilege mapper type to gain full administrative access to the Keycloak realm.

Exploitation requires client registration privileges.


Affected software

Keycloak

How to mitigate CVE-2026-15572

Install security update from vendor's website.

Keycloak - addressed in versions 26.4.14, 26.6.5, 26.7.1

External References

Related Security Bulletins