CVE-2026-4636 Details
Description
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resource. Consequently, the attacker gains unauthorized permissions to victim-owned resources, enabling them to obtain a Requesting Party Token (RPT) and access sensitive information or perform unauthorized actions.
A vulnerability exists in Keycloak that allows an authenticated user with the uma_protection role to bypass User-Managed Access (UMA) policy validation. This flaw enables the user to include resource identifiers from other users in a policy creation request, even if the specified URL path indicates an attacker-owned resource. As a result, the attacker can gain unauthorized access to resources owned by victims, obtain a Requesting Party Token (RPT), and access sensitive information or perform unauthorized actions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-551 | Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | redhat-SADP |
| CWE-551 | Incorrect Behavior Order: Authorization Before Parsing and Canonicalization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | 26.2 26.2.15 26.4 26.4.11 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | CVE Modified | [email protected] |
| Apr 2, 2026 | New CVE Received | [email protected] |