CVE-2026-18201
Received Received - Intake

Keycloak Identity Provider Linking Permission Bypass

Vulnerability report for CVE-2026-18201, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: Red Hat, Inc.

Description

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-30
AI Q&A
2026-07-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Keycloak allows an administrator with permission to manage identity providers to link a new provider to an organization without having the required permissions to manage that organization. This could let an unauthorized administrator influence how users log into specific organizations.

Impact Analysis

An attacker with limited admin access could escalate privileges by linking identity providers to organizations they shouldn't control. This might let them manipulate user authentication processes, potentially redirecting or intercepting logins for affected organizations.

Compliance Impact

This vulnerability could undermine compliance by allowing unauthorized access to authentication systems, potentially violating data protection requirements like GDPR's integrity principle or HIPAA's access controls. Unauthorized login manipulation risks exposing sensitive user data.

Mitigation Strategies

Review and restrict administrative permissions for managing identity providers and organizations. Ensure only authorized administrators have the necessary permissions to prevent unauthorized linking of providers to organizations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18201. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart