What is CVE-2026-18201?
This flaw in Keycloak's administrative API allows an admin with only 'manage identity providers' permission to link a new provider to an organization without the required 'manage organization' permission, leading to a privilege escalation in the permission model. Affected users should apply the latest Keycloak security updates to mitigate this issue.
Azərbaycanca: Keycloak inzibati API-də aşkar edilmiş bu qüsur, identity provider idarə etmə icazəsi olan administratora, təşkilatı idarə etmə icazəsi olmadan belə yeni təminatçını həmin təşkilata bağlamağa imkan verir. Bu, icazə modelində yan keçid (privilege escalation) yaradır. Təsirə məruz qalmamaq üçün Keycloak yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Keycloak
FAQ2
What permission model violation does this Keycloak flaw cause?
The CVE-2026-18201 flaw allows an admin with only 'manage identity providers' permission to link a new identity provider to an organization without the required 'manage organization' permission, causing a privilege escalation.
How can users protect themselves from CVE-2026-18201?
To mitigate this flaw, affected users should apply the latest Keycloak security updates.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.