Description
A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-based policies using tokens that only contain group names rather than full paths. If two groups in different parts of the organization share the same name, a user in the unauthorized group can be mistaken for a member of the authorized group. This can allow a user to gain unauthorized access to protected resources they should not be able to reach.
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Keycloak authorization group policy provider allows tokens that contain only group names to be incorrectly matched against policies that expect full group paths. When two distinct groups share the same name, an unauthenticated or unauthorized user can be mistakenly treated as a member of an authorized group, permitting access to resources they should not be able to reach. This weakness is a clear example of improper authorization control (CWE-285).

Affected Systems

The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign-On 7. No specific product version is listed, so any deployment using these products could be susceptible unless the group policy provider has been validated to require full group paths.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability is of moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, indicating that widespread exploitation is not documented yet. However, the likely attack vector is remote: an attacker could craft or obtain a token containing only ambiguous group names and use it to gain unauthorized access to protected resources. The risk is mitigated only by preventing the use of ambiguous group names or by fixing the policy evaluation logic, for which no current workaround exists. Users should evaluate the potential impact on their usage of group-based policies.

Generated by OpenCVE AI on August 18, 2026 at 12:28 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Identify whether your installation runs Red Hat Build of Keycloak or Red Hat Single Sign‑On 7 and confirm if any group‑policy evaluations use only group names
  • If group policies rely on name‑only tokens, reconfigure policies or token generation to include full group paths, or enforce a strict naming convention that guarantees unique group names across the organization
  • Monitor authentication logs for anomalous access patterns that could indicate misuse of duplicated group names
  • Apply any vendor‑released patch or update regarding this issue as soon as it becomes available; if a patch is not yet released, consider temporarily disabling the affected group‑policy provider or limiting its scope until a fix is deployed

Generated by OpenCVE AI on August 18, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat single Sign-on

Tue, 18 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 18 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue occurs when the system evaluates group-based policies using tokens that only contain group names rather than full paths. If two groups in different parts of the organization share the same name, a user in the unauthorized group can be mistaken for a member of the authorized group. This can allow a user to gain unauthorized access to protected resources they should not be able to reach.
Title Keycloak-services: keycloak-services: name-only group claims let same-name groups satisfy path-specific group policies
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-285
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-18T13:36:37.870Z

Reserved: 2026-08-12T08:50:33.650Z

Link: CVE-2026-19608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T11:16:50.403

Modified: 2026-08-18T15:04:46.610

Link: CVE-2026-19608

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T20:28:49Z

Links: CVE-2026-19608 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:19:11Z

Weaknesses