Description
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Published: 2026-08-05
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker with a standard user account and a limited Initial Access Token can exploit a flaw in Keycloak’s Dynamic Client Registration component. The default policy fails to validate the claim path for User Property mappers, allowing them to write values to internal claim locations. This enables forging administrative roles directly into the user’s access token, giving the attacker the ability to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.

Affected Systems

Affected products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign-On 7. Affected versions were not specified in the advisory, so this vulnerability applies to any releases that retain the default Dynamic Client Registration policy.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, requiring only a valid user account and a standard Initial Access Token. Once the attacker achieves the claim tampering, they can immediately elevate privileges and execute arbitrary administrative actions.

Generated by OpenCVE AI on August 5, 2026 at 15:22 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Restrict or disable User Property mappers in the Dynamic Client Registration policy to prevent unauthorized claim modification.
  • Ensure that Initial Access Tokens are tightly scoped, have the shortest practical lifetime, and are only issued to trusted clients.
  • Apply the latest Red Hat Keycloak patch or upgrade to a version that removes the default DCR policy flaw once it becomes available.

Generated by OpenCVE AI on August 5, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Title Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Jboss Data Grid Jbosseapxp Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-05T14:43:18.846Z

Reserved: 2026-07-17T14:39:05.490Z

Link: CVE-2026-16102

cve-icon Vulnrichment

Updated: 2026-08-05T14:43:14.056Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T15:30:17Z

Weaknesses