What is CVE-2026-18573?
This vulnerability in the keycloak-services component of Keycloak allows improper evaluation of client policies set by a realm administrator for confidential clients. It may enable attackers to bypass specific authentication requirements enforced at the client level.
Azərbaycanca: Keycloak'ın keycloak-services komponentində aşkarlanan bu boşluq, realm administratorunun məxfi müştərilər üçün müəyyən edilmiş autentifikasiya siyasətlərinin düzgün qiymətləndirilməməsinə səbəb olur. Bu səhv konfiqurasiya, müştəri səviyyəsində autentifikasiya tələblərindən yan keçməyə imkan verə bilər.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
How does CVE-2026-18573 affect authentication policies in Keycloak?
This vulnerability causes improper evaluation of client policies set by a realm administrator for confidential clients, potentially allowing attackers to bypass specific authentication requirements enforced at the client level.
In which Keycloak component was CVE-2026-18573 discovered?
This vulnerability was discovered in the keycloak-services component of Keycloak.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.