Bug 2508291 (CVE-2026-18203) - CVE-2026-18203 keycloak-services: keycloak-services: Group policy extendChildren matches sibling group path prefixes
Summary: CVE-2026-18203 keycloak-services: keycloak-services: Group policy extendChild...
Keywords:
Status: NEW
Alias: CVE-2026-18203
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-29 07:49 UTC by OSIDB Bzimport
Modified: 2026-07-31 07:03 UTC (History)
28 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-29 07:49:43 UTC
A flaw was found in the org.keycloak.authorization component of Keycloak. When a group policy is configured with the extendChildren option enabled, the authorization engine performs a raw string prefix match on group paths to determine if a user satisfies the policy requirements. Because the check does not account for path delimiters, a user belonging to a sibling group whose path shares a prefix with the target group (for example, /group-sibling vs /group) is incorrectly granted access. An authenticated attacker with low privileges can exploit this by joining a prefix-colliding sibling group to gain elevated permissions, such as fine-grained admin access or authorization-services rights intended only for the target group and its descendants.


Note You need to log in before you can comment on or make changes to this bug.