{"id":"CVE-2026-15573","published":"2026-08-05T15:16:36.397","lastModified":"2026-08-10T18:40:25.960","description":"A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-178"],"vendors":["redhat"],"products":["build of keycloak","data grid","jboss enterprise application platform expansion pack","single sign-on"],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:50846","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:50847","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:50848","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2026:50849","tags":["Vendor Advisory"]},{"url":"https://access.redhat.com/security/cve/CVE-2026-15573","tags":["Vendor Advisory"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2499593","tags":["Issue Tracking","Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in Keycloak's PathMatcher allows attackers to bypass security policies by manipulating URLs, granting unauthorized access.","exploitability":"Exploitation requires an authenticated user and knowledge of specific URL manipulations; moderately difficult.","blast_radius":"If exploited, this could lead to unauthorized access to administrative or restricted areas within the application.","remediation":"Update Keycloak to a patched version immediately.","tags":["auth-bypass","web","security-policy"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:50:50.118Z"}}