Skip to main content
EPSS 0.3%top 75%

CVE-2026-15573: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Red Hat Red Hat build of Keycloak 26.4

0
High
Published: 08/05/2026 (08/05/2026, 13:50:03 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: Red Hat build of Keycloak 26.4

Description

CVE-2026-15573 is a vulnerability in Red Hat's build of Keycloak 26.4 where the PathMatcher component does not properly normalize URIs before comparing them to security policies. This flaw allows authenticated users to bypass fine-grained authorization controls by manipulating URLs with extra characters such as trailing slashes or matrix parameters, potentially granting access to restricted administrative areas. The vulnerability has a high severity with a CVSS score of 8.1. Red Hat has released version 26.4.14 to address this issue.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected software

Affected versions
<26.4.14>=26.4.0 <26.4.14>=26.6.0 <26.6.5

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 07:01:29 UTC

Technical Analysis

The vulnerability in Red Hat build of Keycloak 26.4 arises from improper URI normalization in the PathMatcher utility responsible for matching request paths to security policies. By exploiting this, an authenticated user can bypass explicit 'Deny' policies and access restricted resources due to the system applying less restrictive security policies when URLs contain extra characters like trailing slashes or matrix parameters. This is classified under CWE-178 and CWE-551, indicating incorrect behavior order and access control issues. Red Hat rates the impact as Important and assigns a CVSS v3.1 score of 8.1 (High).

Potential Impact

Authenticated users can bypass fine-grained authorization controls, allowing unauthorized access to administrative or restricted areas. This compromises confidentiality and integrity of protected systems. There is no impact on availability. The vulnerability requires low privileges and no user interaction, exploitable remotely over the network.

Mitigation Recommendations

Red Hat has released an official security update in Red Hat build of Keycloak version 26.4.14 that fixes this vulnerability. Users should upgrade to version 26.4.14 or later to remediate this issue. Prior to applying the update, back up existing installations and configurations. No other mitigations are specified by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-6j7g-hr6v-3hxc
Osv Schema Version
1.4.0
Aliases
["CVE-2026-15573"]
Database Specific Severity
HIGH
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a738523bf8831d5394efd88

Added to database: 08/05/2026, 18:46:59 UTC

Last enriched: 09/12/2026, 07:01:29 UTC

Last updated: 09/19/2026, 10:01:30 UTC

Views: 109

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses