THREAT OPS › Threat News › [NVD] CVE-2026-18570 (MEDIUM 5.4) — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executo
[NVD] CVE-2026-18570 (MEDIUM 5.4) — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executo
CVE-2026-18570 CVSS: 5.4 MEDIUM Published: 2026-08-02T06:16:41.230
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it
Indicators of compromise
- CVE-2026-18570cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18570