CVE-2026-94215
5.5 MEDIUMPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows administrators with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a controlled realm, potentially exposing client credentials.
- Exploitability
- Exploitation requires an administrator with limited privileges and access to a controlled realm; it is moderately difficult due to the need for precise API manipulation.
- Blast radius
- If exploited, this could lead to significant data exposure and unauthorized administrative actions within the master realm.
- Prioritized remediation
- Update Keycloak to the latest version that includes the fix for CVE-2026-94215.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control. Successful exploitation could lead to the exposure of client credentials or the redirection of administrative login attempts to malicious sites.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L
Weaknesses
CWE-862
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-61746PoC
- MEDIUMCVE-2026-69190PoC
- HIGHCVE-2026-71264PoC
- MEDIUMCVE-2026-77516PoC
- MEDIUMCVE-2026-77518PoC
- LOWCVE-2026-94218
- HIGHCVE-2026-16102
- HIGHCVE-2026-18810PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.