What is CVE-2026-15573?
A flaw in Keycloak's Authorization Services allows attackers to bypass security policies by manipulating URLs with extra characters like trailing slashes due to improper URI normalization in PathMatcher. This may lead to unauthorized access to protected resources. Affected users should apply the vendor's patch when available.
Azərbaycanca: Keycloak-ın Authorization Services komponentində PathMatcher funksiyası URI-ləri normalaşdırmadığı üçün URL-ə əlavə simvol əlavə edərək təhlükəsizlik siyasətlərindən yan keçmək mümkündür. Bu, resurslara icazəsiz girişə səbəb ola bilər. Təsirə məruz qalan sistemlərdə istehsalçının təqdim edəcəyi yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
How does the flaw in Keycloak's PathMatcher function affect URI normalization?
The PathMatcher function does not properly normalize URIs, allowing attackers to bypass security policies by adding extra characters like trailing slashes to URLs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.