Missing Authorization in Keycloak - CVE-2026-18201
Published: July 29, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to influence how users log into specific organizations.
The vulnerability exists due to missing authorization in the administrative API when linking a new identity provider to an organization. A remote privileged user can link a new identity provider to an organization without permission to manage that organization to influence how users log into specific organizations.