PT-2026-66726 · Red Hat · Keycloak

CVE-2026-18211

·

Published

2026-07-31

·

Updated

2026-08-07

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the secure-client-uris client policy executor within Keycloak core services. This component enforces security requirements for client configurations, including the requirement for encrypted connections for redirect URIs. An improper check that validates only the start of a web address instead of properly verifying the host allows an attacker to bypass these restrictions using a specially crafted domain name. This bypass could enable an attacker to intercept sensitive authentication codes over unencrypted connections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18211

Affected Products

Keycloak