Missing Authorization in Keycloak - CVE-2026-18570
Published: August 2, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to obtain tokens with unauthorized role mappings.
The vulnerability exists due to missing authorization in the full-scope-disabled client-policy executor within the keycloak-services component when processing client registration or configuration requests that omit the fullScopeAllowed field. A remote user can omit the fullScopeAllowed field when creating a client to obtain tokens with unauthorized role mappings.