What is CVE-2026-18207?
This flaw exists in Keycloak's client policy enforcement mechanism, where group membership is checked by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different context. Affected systems should be patched immediately.
Azərbaycanca: Bu boşluq Keycloak-ın müştəri siyasət tətbiq mexanizmində qrup üzvlüyünü unikal identifikator əvəzinə ada görə yoxlaması səbəbindən yaranır. Müştəri idarəetmə imtiyazlarına malik hücumçu, fərqli kontekstdə eyni ada malik qrupa qoşularaq təhlükəsizlik siyasətlərini yan keçə bilər. Təsirə məruz qalan sistemlərdə dərhal müvafiq yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Keycloak
FAQ1
How does CVE-2026-18207 allow security policy bypass in Keycloak?
This flaw exists in Keycloak's client policy enforcement mechanism, where group membership is checked by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different context.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.