MEDIUM 5.5 NVD

CVE-2026-18201

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permiss

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.

References

Published: 2026-07-29 · Source: NVD · Feed updated: 2026-08-04
This medium severity vulnerability with a CVSS score of 5.5 was published on 2026-07-29 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.