CVE-2026-15573: Red Hat Build Of Keycloak
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
Affected products
- Red Hat Build Of Keycloak: from 26.4, before 26.4.14 (fixed in 26.4.14); from 26.6, before 26.6.5 (fixed in 26.6.5)
- Red Hat Data Grid: version 8.0 only
- Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
- Red Hat Single Sign-On: version 7.0 only
Published 2026-08-05. Last modified 2026-08-31.