Improper Authorization in Keycloak - CVE-2026-15573

 

Improper Authorization in Keycloak - CVE-2026-15573

Published: August 6, 2026


Vulnerability identifier: #VU141174
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-15573
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authorization and access restricted areas.

The vulnerability exists due to improper access control in the PathMatcher component when handling request paths containing unnormalized URIs. A remote user can send a specially crafted request with a trailing slash or matrix parameters to bypass authorization and access restricted areas.

The issue can cause less restrictive security policies to be applied than intended, including exposure of administrative areas.


Affected software

Keycloak

How to mitigate CVE-2026-15573

Install security update from vendor's website.

Keycloak - addressed in versions 26.4.14, 26.6.5, 26.7.1

External References

Related Security Bulletins