๐Ÿ” CVE Alert

CVE-2026-15572

HIGH 8.8

Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.

CWE CWE-843
Vendor red hat
Product red hat build of keycloak 26.4
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak 26.4

Be the first to know when new high vulnerabilities affecting red hat red hat build of keycloak 26.4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4.14
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6.5
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:50846 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:50847 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:50848 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:50849 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-15572 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2499592

Credits

Red Hat would like to thank Arthur Chan (Ada Logics) for reporting this issue.