THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18570 (MEDIUM 5.4) — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executo

[NVD] CVE-2026-18570 (MEDIUM 5.4) — A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executo

mednvdPublished 2026-08-02

CVE-2026-18570 CVSS: 5.4 MEDIUM Published: 2026-08-02T06:16:41.230

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18570