What is CVE-2026-19608?
A flaw was found in the group policy provider of Keycloak authorization services where tokens containing only group names instead of full paths are used for evaluation. This can lead to incorrect access control decisions if two groups with the same name exist in different paths. Updating to the latest Keycloak version is recommended to mitigate this issue.
Azərbaycanca: Keycloak avtorizasiya xidmətlərinin qrup siyasəti təminatçısında qrup adlarının tam yollar əvəzinə yalnız adlarla qiymətləndirilməsi zəifliyi aşkar edilib. Bu, eyni adda, lakin fərqli yollarda yerləşən qruplar üçün səhv icazə yoxlamalarına səbəb ola bilər. Təsirə məruz qalmamaq üçün Keycloak-ın ən son versiyasına yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Keycloak
FAQ2
How does CVE-2026-19608 affect authorization checks in Keycloak?
Because the group policy provider in Keycloak evaluates tokens using only group names instead of full paths, it can result in incorrect access control decisions if two groups with the same name exist in different paths.
What is the recommended mitigation for CVE-2026-19608?
Updating to the latest version of Keycloak is recommended to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.