Improper Authorization in Keycloak - CVE-2026-15573
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization and access restricted areas.
The vulnerability exists due to improper access control in the PathMatcher component when handling request paths containing unnormalized URIs. A remote user can send a specially crafted request with a trailing slash or matrix parameters to bypass authorization and access restricted areas.
The issue can cause less restrictive security policies to be applied than intended, including exposure of administrative areas.