CVE-2026-15573
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.32%
- CWE
- CWE-551
- Published
- 2026-08-05
- Last modified
- 2026-08-31
Affected products
- Red Hat Red Hat build of Keycloak 26.4
- Red Hat Red Hat build of Keycloak 26.4
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.6
Weakness type
Related vulnerabilities
- CVE-2023-23924 — URI validation failure on SVG parsing in Dompdf
- CVE-2021-34429 — For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
- CVE-2021-28164 — In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
- CVE-2021-28165 — In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re
- CVE-2016-20030 — ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction
- CVE-2023-6394 — Quarkus: graphql operations over websockets bypass
- CVE-2021-31384 — Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the service
- CVE-2021-32779 — Incorrectly handling of URI '#fragment' element as part of the path element