Skip to content
Red HatCVE-2026-15572

Red Hat Keycloak: type confusion

High8.8CVE-2026-15572 · Published Aug 5, 2026 · updated Aug 10, 2026

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat build of Keycloak 26.4.14
Product
all versionsNo fix yet
Red Hat build of Keycloak 26.6.5
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux 10: integer overflow
Low2.2Aug 5
Red Hat RPM: buffer overflow
Medium5.5Aug 5
Red Hat OpenShift Container Platform 4: authentication bypass
Medium6.5Aug 5
Red Hat SAML broker: origin validation error
High7.4Aug 5
Red Hat LDAP storage provider of Keycloak: improper privilege management
Medium5.4Aug 5
Red Hat user-event metrics recording of Keycloak.: resource exhaustion
Medium6.5Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.