What is CVE-2026-16102?
CVE-2026-16102 is a flaw in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing an attacker to write values to sensitive internal claim locations. It is recommended to update to the latest Keycloak version or tighten DCR policies.
Azərbaycanca: CVE-2026-16102 Keycloak identiklik idarəetmə həllinin Dynamic Client Registration (DCR) komponentində aşkarlanmış qüsurdur. Standart DCR siyasəti User Property mapper-ləri üçün claim yolunu düzgün yoxlamadığından, hücumçu həssas daxili claim yerlərinə dəyər yaza bilər. Bu problemi aradan qaldırmaq üçün Keycloak-ın ən son versiyasına yeniləmə və ya DCR siyasətlərini sərtləşdirmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Keycloak
FAQ2
Which component of Keycloak is affected by CVE-2026-16102?
CVE-2026-16102 is a flaw discovered in the Dynamic Client Registration (DCR) component of the Keycloak identity and access management solution.
What can an attacker achieve by exploiting CVE-2026-16102?
Because the default DCR policy fails to properly validate the claim path for User Property mappers, an attacker can write values to sensitive internal claim locations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.