Bug 2537312 (CVE-2026-94215) - CVE-2026-94215 keycloak-services: keycloak-services: Cross-realm client read/write via request-level cache missing realm ownership check
Summary: CVE-2026-94215 keycloak-services: keycloak-services: Cross-realm client read/...
Keywords:
Status: NEW
Alias: CVE-2026-94215
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-21 05:54 UTC by OSIDB Bzimport
Modified: 2026-09-21 05:54 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-21 05:54:29 UTC
A Missing Authorization vulnerability was discovered in Keycloaks Admin REST API. The flaw exists in the way the API resolves client resources using the per-request in-memory cache in the org.keycloak.models.cache.infinispan component. The cache is keyed by client UUID alone and does not perform a realm ownership validation when a resource is retrieved.
An authenticated attacker with the create-realm role in the master realm can exploit this by creating a new realm and then addressing a master realm client using its UUID through the attacker-controlled realms API path. If the master realm client is present in the per-request cache, the system returns or updates the master client instead of enforcing realm boundaries.
Successful exploitation allows an attacker to:
Read client details, including credentials of confidential clients in the master realm.

Overwrite client configurations, such as injecting arbitrary redirect URIs into built-in master clients like admin-cli or security-admin-console.

Turn the master authorization endpoint into an open redirect.

Potentially affect other resource types that utilize the same per-request cache pattern.


Note You need to log in before you can comment on or make changes to this bug.