CVE-2026-18201: Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identi
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18201
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-182010.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18201 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Keycloak provides a
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-18215: Keycloak provides a way to let users log in using Microsoft accounts while restricting access …nvd · 2026-07-31
- lowCVE-2026-18206: A flaw was found in the keycloak-services component of Keycloak, which provides identity and a…nvd · 2026-07-31
- mediumCVE-2026-16093: Keycloak provides a mechanism called Client Policies to enforce security requirements on clien…nvd · 2026-07-17
- mediumCVE-2026-15943: A flaw was found in the Keycloak keycloak-services component, which handles the management of …nvd · 2026-07-17
- mediumCVE-2026-12388: A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to…nvd · 2026-06-30
More from NVD Recent CVEs
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01