Improper Authorization in Keycloak - CVE-2026-15573
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization and access restricted areas.
The vulnerability exists due to improper access control in the PathMatcher component when handling request paths containing unnormalized URIs. A remote user can send a specially crafted request with a trailing slash or matrix parameters to bypass authorization and access restricted areas.
The issue can cause less restrictive security policies to be applied than intended, including exposure of administrative areas.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-15573
Red Hat build of Keycloak - update to 26.6.5