CVE-2026-15572
Received Received - Intake

Keycloak Dynamic Client Registration Privilege Escalation

Vulnerability report for CVE-2026-15572, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Red Hat, Inc.

Description

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
keycloak keycloak *
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-15572 is a flaw in Keycloak's Dynamic Client Registration (DCR) security policy. The 'Allowed Protocol Mapper Types' policy fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by registering an allowed mapper type with a malicious configuration, then swapping it for a restricted, high-privilege mapper type to gain full administrative access to the Keycloak realm.

Detection Guidance

Monitor Keycloak logs for unauthorized client updates or suspicious mapper type changes. Check for clients with unexpected administrative roles or high-privilege mappers. Review DCR API calls for PUT requests that modify mapper types without changing configuration.

Impact Analysis

This vulnerability allows an attacker to escalate privileges and gain full administrative access to the Keycloak realm. This could lead to unauthorized modification of security settings, access to sensitive user data, or causing a denial of service. The impact includes potential data breaches, loss of system integrity, and disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. It may result in data breaches, unauthorized data exposure, and failure to protect personal or health information, leading to legal penalties and reputational damage.

Mitigation Strategies

Disable Dynamic Client Registration if not required. Restrict client registration privileges to trusted users only. Apply Keycloak patches or updates as soon as they become available. Monitor for unauthorized administrative role assignments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15572. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart