CVE-2026-15572Disclosure(redhat / build_of_keycloak)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
build_of_keycloak

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-06: 108-0508-06
Signal classification1 categories
Disclosure
2100.0%
Full discourse2 posts
  • Davtheultimate@davtheultimate
    Disclosure

    Keycloak CVE-2026-15572 score CVSS v3.1 : 8.8 Cette vulnérabilité réside dans la gestion des politiques de sécurité de l'enregistrement dynamique des clients (Dynamic Client Registration - DCR) de Keycloak : La politique "Allowed Protocol Mapper Types" permet aux administrateurs de restreindre le type de mappers de données qu'un client DCR peut associer à ses jetons. Lors d'une mise à jour de configuration d'un client, Keycloak oublie de re-valider le type du mapper si le contenu des attributs de configuration n'a pas changé. Un attaquant disposant des privilèges d'enregistrement de client (via un jeton d'accès initial - Initial Access Token) enregistre d'abord un mapper autorisé (ex: un mapper standard de profil utilisateur) avec des paramètres de rôle hardcodés. Dans un second temps, l'attaquant envoie une requête de mise à jour en remplaçant le type de mapper par un type d'ordinaire interdit (ex: un mapper injectant directement des rôles d'administration) sans modifier le bloc de configuration. La politique valide la requête en ignorant le changement de type, permettant l'escalade de privilèges

    Post summary

    The post discloses that Keycloak’s Dynamic Client Registration policy for allowed protocol mapper types fails to re‑validate the mapper type during configuration updates, enabling attackers with client registration privileges to inject admin roles and elevate privileges.

    0000093
    146 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - Keycloak DCR Protocol Mapper Type Restriction Bypass (CVE-2026-15572) Keycloak Dynamic Client Registration policy enforcement can be bypassed during client updates: if the protocol mapper config is unchanged, the "Allowed Protocol Mapper Types" check isn’t re-applied, letting a registrant first add an allowed mapper then swap its type to a restricted high-privilege mapper to gain realm admin roles and full admin access. 👉Affected: keycloak-rhel9-container; keycloak-rhel9-operator-container; rhbk/keycloak-operator-bundle; rhbk/keycloak-rhel9

    Post summary

    The message announces that Keycloak’s Dynamic Client Registration policy can be bypassed to change protocol mapper types, enabling attackers to gain realm admin rights, and is a high‑severity CVE disclosure with no patches or exploit scripts provided.

    0000091
    282 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more