Impact
Keycloak’s policy enforcer is designed to restrict traffic by matching request URLs against security policies. A flaw in the normalization logic causes requests that contain percent‑encoded characters representing semicolons or directory traversal segments to be misinterpreted. An authenticated user can exploit this by crafting a request with such encoded characters, causing the enforcer to apply a more permissive policy than intended. The result is that the attacker may reach administrative or private application endpoints to which they should not have access. This represents a missing authorization weakness where the system fails to enforce the intended access controls.
Affected Systems
Red Hat Single Sign‑On 7 and the Red Hat builds of Keycloak 26.4, 26.4.16, 26.6, and 26.6.7 running on Enterprise Linux 9 are affected. The issue is present across all listed product variants and versions that include the unpatched policy enforcer component.
Risk and Exploitability
The CVSS score of 8.1 classifies the vulnerability as High severity. The EPSS score of less than 1% indicates that active exploitation is currently rare, yet the flaw remains viable for authenticated users within the target environment. The vulnerability is not yet included in CISA’s KEV catalog, but its impact to business‑critical administrative endpoints warrants immediate attention. An attacker with legitimate user credentials can bypass authorization controls, potentially exposing sensitive data or compromising the integrity of the authentication system.
OpenCVE Enrichment