Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Keycloak - CVE-2026-4636
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized permissions to victim-owned resources.
The vulnerability exists due to authorization before parsing and canonicalization in Keycloak User-Managed Access policy validation when creating a policy with resource identifiers owned by other users. A remote user can include victim-owned resource identifiers in a policy creation request for an attacker-owned resource to gain unauthorized permissions to victim-owned resources.
The user must have the uma_protection role. Successful exploitation can enable acquisition of a Requesting Party Token.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-4636
Red Hat build of Keycloak - addressed in versions 26.2.15, 26.4.11