CVE-2026-15572
Red Hat · Red Hat build of Keycloak
A type confusion flaw in the Dynamic Client Registration security policy management of the Red Hat build of Keycloak allows authenticated users to impact system security.
Executive summary
A type confusion vulnerability in Keycloak allows authenticated attackers to potentially bypass security policies and compromise system integrity.
Vulnerability
This is a type confusion vulnerability (CWE-843) within the Dynamic Client Registration (DCR) policy management. It requires the attacker to have low-level privileges to successfully trigger the flaw and manipulate resource access.
Business impact
With a CVSS score of 8.8, this flaw poses a significant risk to identity management infrastructure. An attacker with minimal privileges could escalate their impact by manipulating client registration policies, potentially leading to unauthorized access to applications relying on Keycloak for authentication.
Remediation
Immediate Action: Update the Red Hat build of Keycloak to the fixed versions (26.4.14-1, 26.4-22, 26.6.5-1, or 26.6-11) as detailed in the Red Hat errata.
Proactive Monitoring: Audit logs for unusual Dynamic Client Registration activities and review changes to client security policies that were not initiated by authorized administrators.
Compensating Controls: Enforce strict access control policies for DCR and limit the number of users with permissions to modify registration settings.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Identity providers are high-value targets. Organizations should treat this vulnerability as critical and ensure that all instances of the Red Hat build of Keycloak are updated to the latest secure versions to prevent potential privilege escalation and unauthorized client registration.