Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15572— Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation

CVSS 8.8 · High EPSS 0.35% · P27

Affected Version Matrix 8

VendorProductVersion RangeStatus
Red HatRed Hat build of Keycloak 26.426.4.14-1< *unaffected
26.4-22< *unaffected
26.4-22< *unaffected
Red HatRed Hat build of Keycloak 26.4.14anyunaffected
Red HatRed Hat build of Keycloak 26.626.6.5-1< *unaffected
26.6-11< *unaffected
26.6-11< *unaffected
Red HatRed Hat build of Keycloak 26.6.5anyunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-15572

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat build of Keycloak 26.4 26.4.14-1 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4.14-cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.6 26.6.5-1 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.5-cpe:/a:redhat:build_keycloak:26.6::el9

II. Public POCs for CVE-2026-15572

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15572

登录查看更多情报信息。

Vendor Advisories for CVE-2026-15572 (6)

Same Patch Batch · Red Hat · 2026-08-05 · 14 CVEs total

CVE-2026-100909.9 CRITICALMulticluster-operators-subscription: multicluster-operators-subscription: namespace edit u
CVE-2026-100599.1 CRITICALCluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cl
CVE-2026-161028.1 HIGHKeycloak-services: keycloak-services: default dcr policy allows role forgery via user prop
CVE-2026-155738.1 HIGHKeycloak-services: keycloak-services: authorization bypass via unnormalized uri matching i
CVE-2026-164427.4 HIGHKeycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only r
CVE-2026-164437.4 HIGHKeycloak-services: keycloak-services: saml broker metadata import disables response signat
CVE-2026-712267.3 HIGHLibkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot ai
CVE-2026-493316.5 MEDIUMOpenshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on
CVE-2026-161006.5 MEDIUMKeycloak-services: keycloak-services: unbounded metric cardinality in user event metrics v
CVE-2026-712256.5 MEDIUMLibkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state rese
CVE-2026-446055.5 MEDIUMRpm: heap buffer overflow in ndb slot table parsing
CVE-2026-160715.4 MEDIUMKeycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users
CVE-2026-712275.1 MEDIUMLibkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandl

IV. Related Vulnerabilities

V. Comments for CVE-2026-15572

No comments yet


Leave a comment