PT-2026-66726 · Red Hat · Keycloak
CVE-2026-18211
·
Published
2026-07-31
·
Updated
2026-08-07
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A flaw exists in the secure-client-uris client policy executor within Keycloak core services. This component enforces security requirements for client configurations, including the requirement for encrypted connections for redirect URIs. An improper check that validates only the start of a web address instead of properly verifying the host allows an attacker to bypass these restrictions using a specially crafted domain name. This bypass could enable an attacker to intercept sensitive authentication codes over unencrypted connections.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak