← Browse

CVE-2026-18201

Low

No strong exploitation signal.

CVSS base
5.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
EPSS — probability of exploitation (30 days)
0.3%
20.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-862
Published 2026-07-29 · modified 2026-09-16

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredHHigh
User InteractionNNone
ScopeUUnchanged
ConfidentialityLLow
IntegrityHHigh
AvailabilityNNone

Timeline

Description

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

Affected

redhat

References

Official: NVD · CVE.org