CVE-2026-15573Disclosure(redhat / build_of_keycloak)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-551CWE-178

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak
  • data_grid
  • jboss_enterprise_application_platform_expansion_pack
  • single_sign-on

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
build_of_keycloakdata_gridjboss_enterprise_application_platform_expansion_packsingle_sign-on

3 versions affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-09: 108-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-15573 - High severity auth bypass in Red Hat Keycloak. URI normalization flaw lets authenticated users bypass policies to access restricted areas. CVSS 8.1. Unpatched - update when available. #CVE #Keycloak #infosec https://www.valtersit.com/cve/CVE-2026-15573 #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu

    Post summary

    The post announces a high severity authentication bypass flaw (CVE-2026‑15573) in Red Keycloak, detailing a URI normalization issue and CVSS 8.1, while noting the vulnerability remains unpatched and will be updated when a fix is released.

    0001056
    1.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---
Appredhatdata_grid8.0--
Appredhatjboss_enterprise_application_platform_expansion_pack---
Appredhatsingle_sign-on7.0--

Explore more