Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26.4::el9 cpe:/a:redhat:build_keycloak:26.6::el9 |
|
| References |
|
Wed, 05 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm. | |
| Title | Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-843 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-05T18:11:41.062Z
Reserved: 2026-07-13T07:36:49.779Z
Link: CVE-2026-15572
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T16:30:12Z
-
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')