CVE-2026-19608
Received Received - Intake

Group Policy Bypass in Keycloak via Group Name Collision

Vulnerability report for CVE-2026-19608, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: redhat-SADP

Description

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-based policies using tokens that only contain group names rather than full paths. If two groups in different parts of the organization share the same name, a user in the unauthorized group can be mistaken for a member of the authorized group. This can allow a user to gain unauthorized access to protected resources they should not be able to reach.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's group policy provider, which controls access to resources. It occurs when group-based policies are evaluated using tokens that only include group names without full paths. If two groups in different parts of an organization share the same name, a user in the unauthorized group may be mistakenly granted access to protected resources meant for the authorized group.

Detection Guidance

To detect this vulnerability, inspect Keycloak group policy configurations and token claims. Check if OIDC group mappers emit only group names without full paths. Verify group name collisions across different paths in your directory service. Review access logs for unauthorized access attempts to protected resources.

Impact Analysis

This vulnerability could allow unauthorized users to gain access to sensitive data or functionality they should not be able to reach. This happens if group names collide across different paths and the system relies on group names alone for access control.

Mitigation Strategies

Immediate mitigation involves updating Keycloak to the latest version or applying patches provided by Red Hat. Ensure OIDC group mappers include full group paths in tokens. Avoid group name collisions by renaming conflicting groups. Monitor access logs for suspicious activity and restrict permissions temporarily.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19608. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart