Description
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Published: 2026-08-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker with a standard user account and a limited Initial Access Token can exploit a flaw in Keycloak’s Dynamic Client Registration component. The default policy fails to validate the claim path for User Property mappers, allowing them to write values to internal claim locations. This enables forging administrative roles directly into the user’s access token, giving the attacker the ability to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.

Affected Systems

Affected products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign-On 7. Affected versions were not specified in the advisory, so this vulnerability applies to any releases that retain the default Dynamic Client Registration policy.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, requiring only a valid user account and a standard Initial Access Token. Once the attacker achieves the claim tampering, they can immediately elevate privileges and execute arbitrary administrative actions.

Generated by OpenCVE AI on August 5, 2026 at 15:22 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Restrict or disable User Property mappers in the Dynamic Client Registration policy to prevent unauthorized claim modification.
  • Ensure that Initial Access Tokens are tightly scoped, have the shortest practical lifetime, and are only issued to trusted clients.
  • Apply the latest Red Hat Keycloak patch or upgrade to a version that removes the default DCR policy flaw once it becomes available.

Generated by OpenCVE AI on August 5, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat data Grid
Redhat single Sign-on
CPEs cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
Vendors & Products Redhat data Grid
Redhat single Sign-on

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
References

Wed, 05 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Title Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Data Grid 8 Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign-on Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-21T13:36:13.996Z

Reserved: 2026-07-17T14:39:05.490Z

Link: CVE-2026-16102

cve-icon Vulnrichment

Updated: 2026-08-05T14:43:14.056Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T15:16:37.703

Modified: 2026-08-21T14:16:48.720

Link: CVE-2026-16102

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-05T02:02:00Z

Links: CVE-2026-16102 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:06:25Z

Weaknesses