CVE-2026-18201
keycloak: Missing Authorization (CVE-2026-18201)
Description
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-862Class
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
cwe.mitre.org →
References & sources
- https://access.redhat.com/security/cve/CVE-2026-18201web
- https://bugzilla.redhat.com/show_bug.cgi?id=2508290web
- https://nvd.nist.gov/vuln/detail/CVE-2026-18201web
- https://access.redhat.com/errata/RHSA-2026:68277vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:68278vendor-advisoryx_refsource_REDHAT
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-16 19:17 UTC· secalert@redhat.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18201.json">CVE-2026-18201</a>
- CVE Modified2026-09-16 16:17 UTC· secalert@redhat.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18201.json">CVE-2026-18201</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:68277
- Reference: https://access.redhat.com/errata/RHSA-2026:68278
- Reference: https://access.redhat.com/security/cve/CVE-2026-18201
- CVE Modified2026-07-29 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-18201","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-07-29 10:16 UTC· secalert@redhat.com
- Affected: Red Hat Build of Keycloak, Red Hat Build of Keycloak, Red Hat Build of Keycloak (+3)
- Description: Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
- CWE: CWE-862