CVE-2026-15573: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Red Hat Red Hat build of Keycloak 26.4
CVE-2026-15573 is a vulnerability in Red Hat's build of Keycloak 26.4 where the PathMatcher component does not properly normalize URIs before comparing them to security policies. This flaw allows authenticated users to bypass fine-grained authorization controls by manipulating URLs with extra characters such as trailing slashes or matrix parameters, potentially granting access to restricted administrative areas. The vulnerability has a high severity with a CVSS score of 8.1. Red Hat has released version 26.4.14 to address this issue.
AI Analysis
Technical Summary
The vulnerability in Red Hat build of Keycloak 26.4 arises from improper URI normalization in the PathMatcher utility responsible for matching request paths to security policies. By exploiting this, an authenticated user can bypass explicit 'Deny' policies and access restricted resources due to the system applying less restrictive security policies when URLs contain extra characters like trailing slashes or matrix parameters. This is classified under CWE-178 and CWE-551, indicating incorrect behavior order and access control issues. Red Hat rates the impact as Important and assigns a CVSS v3.1 score of 8.1 (High).
Potential Impact
Authenticated users can bypass fine-grained authorization controls, allowing unauthorized access to administrative or restricted areas. This compromises confidentiality and integrity of protected systems. There is no impact on availability. The vulnerability requires low privileges and no user interaction, exploitable remotely over the network.
Mitigation Recommendations
Red Hat has released an official security update in Red Hat build of Keycloak version 26.4.14 that fixes this vulnerability. Users should upgrade to version 26.4.14 or later to remediate this issue. Prior to applying the update, back up existing installations and configurations. No other mitigations are specified by the vendor.
CVE-2026-15573: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Red Hat Red Hat build of Keycloak 26.4
Description
CVE-2026-15573 is a vulnerability in Red Hat's build of Keycloak 26.4 where the PathMatcher component does not properly normalize URIs before comparing them to security policies. This flaw allows authenticated users to bypass fine-grained authorization controls by manipulating URLs with extra characters such as trailing slashes or matrix parameters, potentially granting access to restricted administrative areas. The vulnerability has a high severity with a CVSS score of 8.1. Red Hat has released version 26.4.14 to address this issue.
CVSS v3.1
Score 8.1high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Red Hat build of Keycloak 26.4 arises from improper URI normalization in the PathMatcher utility responsible for matching request paths to security policies. By exploiting this, an authenticated user can bypass explicit 'Deny' policies and access restricted resources due to the system applying less restrictive security policies when URLs contain extra characters like trailing slashes or matrix parameters. This is classified under CWE-178 and CWE-551, indicating incorrect behavior order and access control issues. Red Hat rates the impact as Important and assigns a CVSS v3.1 score of 8.1 (High).
Potential Impact
Authenticated users can bypass fine-grained authorization controls, allowing unauthorized access to administrative or restricted areas. This compromises confidentiality and integrity of protected systems. There is no impact on availability. The vulnerability requires low privileges and no user interaction, exploitable remotely over the network.
Mitigation Recommendations
Red Hat has released an official security update in Red Hat build of Keycloak version 26.4.14 that fixes this vulnerability. Users should upgrade to version 26.4.14 or later to remediate this issue. Prior to applying the update, back up existing installations and configurations. No other mitigations are specified by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6j7g-hr6v-3hxc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-15573"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a738523bf8831d5394efd88
Added to database: 08/05/2026, 18:46:59 UTC
Last enriched: 09/12/2026, 07:01:29 UTC
Last updated: 09/19/2026, 10:01:30 UTC
Views: 109
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.