CVE-2026-18201

keycloak: Missing Authorization (CVE-2026-18201)

mediumEPSS 0.4%

Description

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamikeycloak

Metrics

5.5
Source: nvd-v3
30.3 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-31 14:37 UTC
CWE-862

Weakness classes (CWE)

  • CWE-862Class

    Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-16 19:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18201.json">CVE-2026-18201</a>
  2. CVE Modified2026-09-16 16:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/18xxx/CVE-2026-18201.json">CVE-2026-18201</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:68277
    • Reference: https://access.redhat.com/errata/RHSA-2026:68278
    • Reference: https://access.redhat.com/security/cve/CVE-2026-18201
  3. CVE Modified2026-07-29 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-18201","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  4. New CVE Received2026-07-29 10:16 UTC· secalert@redhat.com
    • Affected: Red Hat Build of Keycloak, Red Hat Build of Keycloak, Red Hat Build of Keycloak (+3)
    • Description: Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
    • CWE: CWE-862