CVE-2026-16102
Received Received - Intake

Keycloak Role Forgery via DCR Policy Misconfiguration

Vulnerability report for CVE-2026-16102, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Red Hat, Inc.

Description

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat keycloak *
keycloak keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's Dynamic Client Registration (DCR) component. It allows attackers with a standard user account to forge administrative roles in their access token by exploiting improper validation of claim paths for User Property mappers. This can lead to unauthorized access and control over the system.

Detection Guidance

To detect CVE-2026-16102, monitor Keycloak logs for suspicious Dynamic Client Registration (DCR) activities. Check for unauthorized client registrations or modifications to `resource_access` claims. Review tokens for unexpected administrative role assignments in paths like `resource_access.realm-management.roles`.

Impact Analysis

An attacker could take over other clients, steal confidential secrets, and gain full administrative control over the realm. This means unauthorized access to sensitive data and system functions, potentially leading to data breaches or system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR and HIPAA. It may result in data breaches, unauthorized disclosures, and failure to protect personal or health information as mandated by these regulations.

Mitigation Strategies

Update Keycloak to the latest version that patches this vulnerability. Review and restrict User Property mappers to prevent unauthorized access to sensitive claims. Audit access tokens for suspicious administrative role assignments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16102. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart