Description
A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Published: 2026-08-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Dynamic Client Registration component of Keycloak allows an attacker with a standard user account and a limited Initial Access Token to write values to sensitive internal claim locations by exploiting the default DCR policy’s lack of claim‑path validation for User Property mappers. This gives the attacker the ability to forge administrative roles in their own access token, thereby taking over other clients, stealing confidential secrets, and potentially assuming full administrative control over the realm. The weakness is reflected in the CWE identifiers 284 and 551.

Affected Systems

Affected products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and Red Hat Single Sign‑On 7. The specific affected Keycloak builds are 26.4, 26.4.14, 26.6 and 26.6.5; Data Grid is version 8; Single Sign‑On is 7.0; the expansion pack version is not specified but all releases with the default DCR policy are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score is below 1 %, showing a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is remote, requiring only a valid user credential and a standard Initial Access Token. Once the attacker writes the forged administrative claims, they immediately elevate privileges and can perform arbitrary administrative actions on the realm.

Generated by OpenCVE AI on August 31, 2026 at 16:36 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the official Red Hat update that removes the default DCR policy flaw or upgrade to a Keycloak release that contains the fix once it becomes available.
  • Restrict or disable User Property mappers in the Dynamic Client Registration configuration to prevent unauthorized claim modification.
  • Ensure that Initial Access Tokens are issued only to trusted clients, have the shortest feasible lifetime, and contain the minimal necessary scopes.
  • No CNA‑provided workaround is available; rely on the official patch and monitor vendor advisories.

Generated by OpenCVE AI on August 31, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Mon, 31 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-551

Tue, 11 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat data Grid
Redhat single Sign-on
CPEs cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
Vendors & Products Redhat data Grid
Redhat single Sign-on

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
References

Wed, 05 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user account and a limited Initial Access Token can exploit this to forge administrative roles in their access token. This allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Title Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Data Grid 8 Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign-on Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-31T11:25:12.555Z

Reserved: 2026-07-17T14:39:05.490Z

Link: CVE-2026-16102

cve-icon Vulnrichment

Updated: 2026-08-05T14:43:14.056Z

cve-icon NVD

Status : Modified

Published: 2026-08-05T15:16:37.703

Modified: 2026-08-31T12:17:54.960

Link: CVE-2026-16102

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-05T02:02:00Z

Links: CVE-2026-16102 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-551

    Incorrect Behavior Order: Authorization Before Parsing and Canonicalization