cvedb.io
CVE-2026-18207
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2026-07-29T10:16:40.770 · Last modified 2026-07-29T10:16:40.770

Summary

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attacker with client management privileges could bypass security policies by joining a group with a matching name in a different part of the group hierarchy, potentially allowing them to register or update clients without following required security hardening profiles.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.