CVE-2026-15573: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Red Hat Red Hat build of Keycloak 26.4
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
AI Analysis
Technical Summary
The vulnerability exists in Keycloak's Authorization Services PathMatcher component, which fails to normalize URIs before matching them to security policies. This improper normalization allows an authenticated attacker to craft URLs with additional characters (e.g., trailing slashes or matrix parameters) that cause the system to apply less restrictive security policies than intended. Consequently, this enables bypass of explicit "Deny" policies and unauthorized access to restricted or administrative resources. Red Hat rates this vulnerability as Important and assigns a CVSS v3.1 score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). The issue affects the Red Hat build of Keycloak 26.4, and a security update is available in version 26.4.14. The vendor advisory and errata provide detailed information and remediation instructions.
Potential Impact
Authenticated users with low privileges can exploit this vulnerability to bypass fine-grained authorization controls and gain unauthorized access to administrative or restricted areas. This poses a significant risk to the confidentiality and integrity of the protected system. There is no indication of impact on availability. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released an updated package, Red Hat build of Keycloak 26.4.14, which addresses this vulnerability along with other security issues. Users should back up their existing installations and apply the update promptly to remediate the issue. No alternative mitigations are specified in the advisory. Patch status is confirmed by the vendor advisory and errata.
CVE-2026-15573: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization in Red Hat Red Hat build of Keycloak 26.4
Description
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
CVSS v3.1
Score 8.1high
Affected software
Red Hat
Red Hat build of Keycloak 26.4
Red Hat
Red Hat build of Keycloak 26.4
Red Hat
Red Hat build of Keycloak 26.4.14
Red Hat
Red Hat build of Keycloak 26.6
Red Hat
Red Hat build of Keycloak 26.6
Red Hat
Red Hat build of Keycloak 26.6.5
Red Hat
Red Hat Data Grid 8
Red Hat
Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat
Red Hat Single Sign-On 7
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in Keycloak's Authorization Services PathMatcher component, which fails to normalize URIs before matching them to security policies. This improper normalization allows an authenticated attacker to craft URLs with additional characters (e.g., trailing slashes or matrix parameters) that cause the system to apply less restrictive security policies than intended. Consequently, this enables bypass of explicit "Deny" policies and unauthorized access to restricted or administrative resources. Red Hat rates this vulnerability as Important and assigns a CVSS v3.1 score of 8.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). The issue affects the Red Hat build of Keycloak 26.4, and a security update is available in version 26.4.14. The vendor advisory and errata provide detailed information and remediation instructions.
Potential Impact
Authenticated users with low privileges can exploit this vulnerability to bypass fine-grained authorization controls and gain unauthorized access to administrative or restricted areas. This poses a significant risk to the confidentiality and integrity of the protected system. There is no indication of impact on availability. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released an updated package, Red Hat build of Keycloak 26.4.14, which addresses this vulnerability along with other security issues. Users should back up their existing installations and apply the update promptly to remediate the issue. No alternative mitigations are specified in the advisory. Patch status is confirmed by the vendor advisory and errata.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-13T07:37:48.551Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-15573","vendor":"Red Hat"}]
Threat ID: 6a734bccbf8831d53906d974
Added to database: 08/05/2026, 14:42:20 UTC
Last enriched: 08/12/2026, 15:09:43 UTC
Last updated: 09/19/2026, 22:01:32 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.