← Back to search

CVE-2026-94215

5.5 MEDIUM

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows administrators with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a controlled realm, potentially exposing client credentials.
Exploitability
Exploitation requires an administrator with limited privileges and access to a controlled realm; it is moderately difficult due to the need for precise API manipulation.
Blast radius
If exploited, this could lead to significant data exposure and unauthorized administrative actions within the master realm.
Prioritized remediation
Update Keycloak to the latest version that includes the fix for CVE-2026-94215.
apiadmin-rightsconfig-exposureidentity-management

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control. Successful exploitation could lead to the exposure of client credentials or the redirection of administrative login attempts to malicious sites.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L

Weaknesses

CWE-862

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.