CVE-2026-18570General(redhat / build_of_keycloak)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
build_of_keycloak

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-02: 3Technical Details · 2026-08-02: 208-02
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-18570 A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security polici… https://www.cve.org/CVERecord?id=CVE-2026-18570 ----- Traducción: Se encontró una fa… http://infoflow.cloud`

    Post summary

    The post mentions a newly discovered flaw in Keycloak’s keycloak-services component but provides no detailed technical information, PoC, exploit, or remediation.

    0000058
    96 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-18570 A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security polici… https://www.cve.org/CVERecord?id=CVE-2026-18570

    Post summary

    The snippet announces CVE-2026-18570 as a flaw in Keycloak’s client-policy executor, but does not provide evidence of exploitation, a PoC, or a patch.

    00000529
    57.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-18570 Policy Bypass in Red Hat Build of Keycloak Client-Policy Executor https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-18570

    Post summary

    The entry announces a policy bypass vulnerability (CVE‑2026‑18570) affecting Red Hat’s Keycloak Client‑Policy Executor, offering minimal technical context but no additional exploitation or patch information.

    00000128
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more