CVE-2026-94215 Overview
CVE-2026-94215 is a missing authorization flaw [CWE-862] in the Admin REST API of Keycloak, the open-source identity and access management platform. The API resolves clients using a per-request in-memory cache keyed by unique identifier without validating that the resolved client belongs to the realm specified in the request path. An authenticated administrator with limited privileges in one realm can read or modify client configurations in other realms, including the master realm. Successful exploitation exposes client credentials or allows redirection of administrative login flows to attacker-controlled endpoints.
Critical Impact
A tenant-scoped admin can pivot into the master realm to steal client secrets or hijack administrative authentication flows.
Affected Products
- Keycloak (open-source identity and access management)
- Red Hat build of Keycloak
- Red Hat Single Sign-On downstream distributions
Discovery Timeline
- 2026-09-21 - CVE-2026-94215 published to NVD
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-94215
Vulnerability Analysis
Keycloak enforces multi-tenant isolation through realms. Each realm owns a distinct set of clients, roles, and administrators. The Admin REST API exposes endpoints under /admin/realms/{realm}/clients/{client-id} to manage client configurations within a specified realm.
The vulnerability arises because the API resolves the target client from a per-request in-memory cache using only the client's unique identifier. The realm path parameter is not cross-checked against the resolved client's owning realm. An administrator authenticated to a realm they control can therefore reference client identifiers belonging to another realm, including master, and receive or mutate their configuration.
Impact scenarios include disclosure of client secrets used for confidential OAuth flows and modification of redirect_uri values on master-realm administrative clients. Redirecting the admin console's login flow to a malicious host allows an attacker to capture authorization codes or tokens issued to platform administrators.
Root Cause
The root cause is missing authorization [CWE-862] at the object-resolution layer. The lookup trusts the client identifier alone and skips a realm-membership check before returning the object. This is a broken access control pattern where authentication succeeds but object-level authorization is not enforced for cross-tenant references.
Attack Vector
Exploitation requires network access to the Admin REST API and valid credentials for an account holding administrative privileges in any realm. The attacker crafts requests to admin endpoints substituting the client UUID of a client in another realm. Because the resolver ignores the realm path segment, the API returns or updates the foreign client. Exploitation complexity is elevated because the attacker must know or enumerate valid client identifiers in the target realm. See the Red Hat CVE-2026-94215 advisory for further technical context.
Detection Methods for CVE-2026-94215
Indicators of Compromise
- Admin REST API requests where the authenticated user's realm differs from the realm segment or resolved client's realm in the response.
- Unexpected GET or PUT requests to /admin/realms/{realm}/clients/{uuid} targeting the master realm from non-master admin accounts.
- Modifications to redirectUris, webOrigins, or clientAuthenticatorType fields on master-realm clients from unusual source identities.
- Read operations returning secret fields for clients not owned by the requesting admin's realm.
Detection Strategies
- Correlate Keycloak admin event logs (ADMIN_EVENT) against the acting admin's realm assignment and flag operations that touch clients in other realms.
- Baseline which admins legitimately manage each realm and alert on cross-realm client resource access.
- Inspect reverse-proxy and API gateway logs for admin API paths that reference the master realm from tenants that should never reach it.
Monitoring Recommendations
- Enable full Keycloak admin event logging with includeRepresentation=true to capture before/after client configuration payloads.
- Forward Keycloak audit logs to a centralized SIEM for correlation with authentication and network telemetry.
- Alert on any change to master-realm client redirectUris, rootUrl, or baseUrl attributes.
How to Mitigate CVE-2026-94215
Immediate Actions Required
- Apply the vendor-provided Keycloak update as soon as it is available in your distribution channel.
- Rotate client secrets for confidential clients in the master realm and any realm containing sensitive administrative clients.
- Audit redirectUris and webOrigins on all master-realm clients and revert any unauthorized changes.
- Review admin event history for cross-realm client access since the vulnerable version was deployed.
Patch Information
Refer to the Red Hat CVE-2026-94215 advisory and Red Hat Bug #2537312 for fixed package versions and errata. Upstream Keycloak users should upgrade to the release that includes the realm-membership check in the client resolver.
Workarounds
- Restrict Admin REST API network exposure to trusted management networks and require mutual TLS or VPN access.
- Minimize the number of accounts with realm-admin privileges and remove unused admin accounts from non-production realms.
- Enforce strong multi-factor authentication on all administrative accounts to raise the bar for the required foothold.
- Segment tenants so that shared Keycloak instances do not host both untrusted tenant admins and the platform's master realm.
# Example: restrict admin endpoints at a reverse proxy
# Only allow /admin/* from a management CIDR
location /admin/ {
allow 10.0.10.0/24;
deny all;
proxy_pass http://keycloak_upstream;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.