Missing Authorization in Keycloak - CVE-2026-18573
Published: August 2, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to bypass client authentication policies.
The vulnerability exists due to improper authorization in the keycloak-services component when updating a public client to a confidential client. A remote user can create a public client and update it to a confidential client with weaker authentication to bypass client authentication policies.
Exploitation requires client management permissions and realm client policies that enforce authentication requirements on confidential clients.