CVE-2026-15572: Access of Resource Using Incompatible Type ('Type Confusion') in Red Hat Red Hat build of Keycloak 26.4
A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.
AI Analysis
Technical Summary
The vulnerability exists in Keycloak's DCR security policy where the "Allowed Protocol Mapper Types" policy does not re-validate the mapper type if the configuration remains unchanged during client updates. An attacker can exploit this by initially registering an allowed mapper type with a malicious configuration and then swapping it for a restricted mapper type that grants administrative privileges. This type confusion leads to privilege escalation, allowing the attacker to gain full administrative control over the Keycloak realm. The CVSS v3.1 score is 8.8 (high), reflecting network attack vector, low attack complexity, required privileges, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation grants an attacker with client registration privileges the ability to escalate their privileges to full administrative access within the Keycloak realm. This compromises the confidentiality, integrity, and availability of the authentication and authorization services managed by Keycloak, potentially affecting all applications relying on it for identity management.
Mitigation Recommendations
Red Hat has released updated packages for Red Hat build of Keycloak 26.4.14 that address this vulnerability. Users should apply these security updates promptly. Before updating, back up existing installations including applications, configuration files, and databases. No alternative mitigations or workarounds are specified in the vendor advisory. Patch status is confirmed by Red Hat advisories RHSA-2026:50846 and RHSA-2026:50847.
CVE-2026-15572: Access of Resource Using Incompatible Type ('Type Confusion') in Red Hat Red Hat build of Keycloak 26.4
Description
A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm.
CVSS v3.1
Score 8.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in Keycloak's DCR security policy where the "Allowed Protocol Mapper Types" policy does not re-validate the mapper type if the configuration remains unchanged during client updates. An attacker can exploit this by initially registering an allowed mapper type with a malicious configuration and then swapping it for a restricted mapper type that grants administrative privileges. This type confusion leads to privilege escalation, allowing the attacker to gain full administrative control over the Keycloak realm. The CVSS v3.1 score is 8.8 (high), reflecting network attack vector, low attack complexity, required privileges, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation grants an attacker with client registration privileges the ability to escalate their privileges to full administrative access within the Keycloak realm. This compromises the confidentiality, integrity, and availability of the authentication and authorization services managed by Keycloak, potentially affecting all applications relying on it for identity management.
Mitigation Recommendations
Red Hat has released updated packages for Red Hat build of Keycloak 26.4.14 that address this vulnerability. Users should apply these security updates promptly. Before updating, back up existing installations including applications, configuration files, and databases. No alternative mitigations or workarounds are specified in the vendor advisory. Patch status is confirmed by Red Hat advisories RHSA-2026:50846 and RHSA-2026:50847.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-13T07:36:49.779Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2026:50846","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:50847","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:50848","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:50849","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2026-15572","vendor":"Red Hat"}]
Threat ID: 6a736b64bf8831d5392da645
Added to database: 08/05/2026, 16:57:08 UTC
Last enriched: 08/05/2026, 17:11:14 UTC
Last updated: 08/06/2026, 01:27:48 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.