Description
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
Published: 2026-08-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Keycloak’s PathMatcher component causes the system to compare request paths without normalizing the URI. An attacker can append a trailing slash or matrix parameters to a URL, which tricks the system into applying a less restrictive security policy. The result is that an authenticated user can access administrative or restricted areas that they should not be able to see, providing an unauthorized privilege escalation.

Affected Systems

The vulnerability affects Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. The CNA identified these products, but specific affected versions are not listed; administrators should verify whether their installations are within the affected range.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known public exploitation. The attack requires an authenticated session, and the attacker must craft a request with a non‑normalized URI to bypass authorization. Because the flaw is tied to path normalization, exploitation is limited to URLs within the application’s controlled domain.

Generated by OpenCVE AI on August 5, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Red Hat security update for Red Hat Build of Keycloak, Data Grid 8, JBoss EAP Expansion Pack, or Single Sign‑On 7 that addresses the PathMatcher normalization issue.
  • If an immediate patch is unavailable, configure your web server or reverse proxy to strip trailing slashes and matrix parameters from incoming requests before forwarding them to Keycloak, forcing strict URI normalization.
  • Review and tighten all authorization policies to ensure that no policy can be applied based on unnormalized paths; limit authenticated users to the minimum roles required for administrative functions.

Generated by OpenCVE AI on August 5, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on

Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 05 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-178
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
References

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 05 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
Title Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Data Grid 8 Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-20T10:50:40.515Z

Reserved: 2026-07-13T07:37:48.551Z

Link: CVE-2026-15573

cve-icon Vulnrichment

Updated: 2026-08-05T15:43:21.706Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T15:16:36.397

Modified: 2026-08-20T11:16:20.427

Link: CVE-2026-15573

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-05T02:02:00Z

Links: CVE-2026-15573 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:30:11Z

Weaknesses
  • CWE-178

    Improper Handling of Case Sensitivity

  • CWE-285

    Improper Authorization