HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-15572 — A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy...

·Source: NIST NVD

Updated:

Executive Summary

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an all

Analysis

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an allowed mapper type with a malicious configuration and then swapping it for a restricted, high-privilege mapper type (such as one that hardcodes administrative roles). This allows the attacker to gain full administrative access to the Keycloak realm. CVSS Score: 8.8. Published: 2026-08-05T16:16:50.903.

Indicators of Compromise (1)

CVE (1)
CVE-2026-15572
Source Attribution

Originally published by NIST NVD on Aug 5, 2026. Verified by: NIST.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-18991 — A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. Th...

A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report b

CVE-2026-18991
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-18990 — A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown ...

A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18990
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-18973 — A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The ...

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early

CVE-2026-18973
NIST NVD