What is CVE-2026-18203?
A vulnerability was found in the group policy evaluation logic of Keycloak, an identity and access management solution. The flaw incorrectly uses a text-based prefix check for group membership, potentially allowing a user to extend permissions to child groups they should not access. Affected deployments should review group policies and apply Keycloak updates immediately.
Azərbaycanca: Keycloak identiklik və giriş idarəetmə sistemində qrup siyasətinin qiymətləndirilməsində qüsur aşkar edilib. Qüsur, qrup adının mətn prefiksi kimi yoxlanılması səbəbindən istifadəçinin aid olmadığı alt qruplara icazələri genişləndirə bilər. Təsirə məruz qalan sistemlərdə qrup siyasətlərini nəzərdən keçirmək və Keycloak yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Keycloak
FAQ1
How does CVE-2026-18203 affect user permissions in Keycloak?
The vulnerability can extend a user's permissions to child groups they should not access due to an incorrect text-based prefix check for group membership.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.