HIGH🇵🇱 Wersja polska

CVE-2026-15573

CVSS 8.1v3.1pub. 2026-08-05upd. 2026-08-31

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Red Hat Build Of Keycloak

    APP
    Redhat
    26.4 – 26.4.14 (excl.)26.6 – 26.6.5 (excl.)
  • Red Hat Data Grid

    APP
    Redhat
    8.0
  • Red Hat Jboss Enterprise Application Platform Expansion Pack

    APP
    Redhat
    all versions
  • Red Hat Single Sign On

    APP
    Redhat
    7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-12543CRITICAL9.6PL ✓same product

Brak walidacji nagłówka Host w serwerze Undertow HTTP

CVE-2022-4361CRITICAL10.0PL ✓same product

XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów

CVE-2021-31917CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia REST w Red Hat DataGrid i Infinispan

CVE-2019-14887CRITICAL9.1PL ✓same product

Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade

CVE-2019-14837CRITICAL9.1PL ✓same product

Keycloak: przejęcie konta przez domenę placeholder.org przed wersją 8.0.0