High · published August 5, 2026
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.
| Product | Versions | Fixed in |
|---|---|---|
| redhat/build_of_keycloak | ≥ 26.4, < 26.4.14 | 26.4.14 |
| redhat/build_of_keycloak | ≥ 26.6, < 26.6.5 | 26.6.5 |
| redhat/data_grid | all versions | — |
| redhat/jboss_enterprise_application_platform_expansion_pack | all versions | — |
| redhat/single_sign-on | all versions | — |