Record summary

CVE-2026-18570 has a selected CVSS score of 5.4 (medium).

Description

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakkeycloak-services

Default status: affected

CVE ListVersion data not supplied

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat Build of Keycloak

Browse Red Hat / Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9

Default status: affected

CVE ListVersion data not supplied

Red Hat Data Grid 8

Browse Red Hat / Red Hat Data Grid 8keycloak-services

Default status: unaffected

CVE ListVersion data not supplied

Red Hat JBoss Enterprise Application Platform Expansion Pack

Browse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-services

Default status: unaffected

CVE ListVersion data not supplied

Red Hat Single Sign-On 7

Browse Red Hat / Red Hat Single Sign-On 7keycloak-services

Default status: unaffected

CVE ListVersion data not supplied

References

3