What is CVE-2026-18570?
A security flaw was discovered in the full-scope-disabled client-policy executor within the keycloak-services component of Red Hat Build of Keycloak. This issue may lead to improper enforcement of security policies during client registration when full scope is disabled. It is recommended to update the affected versions as per vendor guidance.
Azərbaycanca: CVE-2026-18570 Red Hat Build of Keycloak məhsulunda 'keycloak-services' komponenti daxilində 'full-scope-disabled client-policy executor' funksiyasında tapılmış bir zəiflikdir. Bu qüsur, təhlükəsizlik siyasətlərinin tam əhatə dairəsi söndürüldükdə düzgün tətbiq edilməməsinə səbəb ola bilər. Təsirə məruz qalan versiyaları yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Red Hat
FAQ2
In which component of Red Hat Build of Keycloak was CVE-2026-18570 discovered?
This flaw was discovered in the full-scope-disabled client-policy executor within the keycloak-services component.
What outcome can result from exploiting CVE-2026-18570?
This issue may lead to improper enforcement of security policies when full scope is disabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.