CVE-2026-15573: Red Hat Build Of Keycloak

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.

Affected products

  • Red Hat Build Of Keycloak: from 26.4, before 26.4.14 (fixed in 26.4.14); from 26.6, before 26.6.5 (fixed in 26.6.5)
  • Red Hat Data Grid: version 8.0 only
  • Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
  • Red Hat Single Sign-On: version 7.0 only

Published 2026-08-05. Last modified 2026-08-31.