Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-16102— Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers

Quick assessment

Affected
Red Hat Red Hat build of Keycloak 26.4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Keycloak Keycloak是Keycloak组织开源的一款身份认证与权限管理软件。 Keycloak存在安全漏洞,该漏洞源于Dynamic Client Registration (DCR)组件中的默认DCR策略未能正确验证用户属性映射器的声明路径,导致具有标准用户帐户和有限初始访问令牌的攻击者能够伪造管理角色,从而接管其他客户端、窃取机密秘密,并可能获得领域的完全管理控制。

CVSS 8.1 · High EPSS 0.46% · P38

Affected Version Matrix 14

VendorProduct Version RangeStatus
Red Hat Red Hat build of Keycloak 26.4 26.4.14-1< * unaffected
26.4-22< * unaffected
26.4-22< * unaffected
Red Hat Red Hat build of Keycloak 26.4.14 any unaffected
any unaffected
Red Hat Red Hat build of Keycloak 26.6 26.6.5-1< * unaffected
26.6-11< * unaffected
26.6-11< * unaffected
Red Hat Red Hat build of Keycloak 26.6.5 any unaffected
any unaffected
any unaffected
Red Hat Red Hat Data Grid 8 any unaffected
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack any unaffected
Red Hat Red Hat Single Sign-On 7 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16102

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不正确的行为次序:在解析与净化处理之前进行授权
Source: CVE Program / CVE List V5
Vulnerability Title
Keycloak 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Keycloak Keycloak是Keycloak组织开源的一款身份认证与权限管理软件。 Keycloak存在安全漏洞,该漏洞源于Dynamic Client Registration (DCR)组件中的默认DCR策略未能正确验证用户属性映射器的声明路径,导致具有标准用户帐户和有限初始访问令牌的攻击者能够伪造管理角色,从而接管其他客户端、窃取机密秘密,并可能获得领域的完全管理控制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat build of Keycloak 26.4 26.4.14-1 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4.14 - cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.4.14 - cpe:/a:redhat:build_keycloak:26.4::el9
Red Hat Red Hat build of Keycloak 26.6 26.6.5-1 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.5 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.5 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat build of Keycloak 26.6.5 - cpe:/a:redhat:build_keycloak:26.6::el9
Red Hat Red Hat Data Grid 8 - cpe:/a:redhat:jboss_data_grid:8
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack - cpe:/a:redhat:jbosseapxp
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-16102

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16102

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-16102 (6)

Same Patch Batch · Red Hat · 2026-08-05 · 11 CVEs total

CVE-2026-10059 9.1 CRITICAL Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cl
CVE-2026-10090 9.0 CRITICAL Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit u
CVE-2026-15572 8.8 HIGH Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows p
CVE-2026-15573 8.1 HIGH Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching i
CVE-2026-16443 7.4 HIGH Keycloak-services: keycloak-services: saml broker metadata import disables response signat
CVE-2026-16442 7.4 HIGH Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only r
CVE-2026-16100 6.5 MEDIUM Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics v
CVE-2026-49331 6.5 MEDIUM Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on
CVE-2026-44605 5.5 MEDIUM Rpm: heap buffer overflow in ndb slot table parsing
CVE-2026-16071 5.4 MEDIUM Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users

IV. Related Vulnerabilities

V. Comments for CVE-2026-16102

No comments yet


Leave a comment