What is CVE-2026-15572?
CVE-2026-15572 is a flaw in Keycloak's Dynamic Client Registration (DCR) where the "Allowed Protocol Mapper Types" policy fails to re-validate mapper types during client updates if the configuration remains unchanged. This allows attackers to potentially bypass security restrictions by using restricted mappers, requiring immediate patching by Keycloak administrators.
Azərbaycanca: CVE-2026-15572 Keycloak-in Dinamik Müştəri Qeydiyyatı (DCR) funksionallığında aşkarlanmış boşluqdur. Bu qüsur "Allowed Protocol Mapper Types" siyasətinin müştəri yeniləməsi zamanı mapper növünü düzgün təkrar yoxlamaması ilə bağlıdır. Bu zəiflikdən istifadə edən hücumçu məhdudlaşdırılmış mapper-ləri istifadə edərək təhlükəsizlik məhdudiyyətlərini keçə bilər, bu səbəbdən Keycloak administratorları təcili yeniləmə tətbiq etməlidir.
FAQ2
Which Keycloak functionality is affected by CVE-2026-15572?
CVE-2026-15572 is a security flaw found in Keycloak's Dynamic Client Registration (DCR) functionality.
How can an attacker exploit this vulnerability?
An attacker can exploit the failure of the 'Allowed Protocol Mapper Types' policy to properly re-validate mapper types during client updates, using restricted mappers to bypass security restrictions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.