CVE-2026-18573: Keycloak Client Policy Bypass Vulnerability
A medium-severity vulnerability (CVSS 6.5) was discovered in the keycloak-services component of Red Hat Build of Keycloak. The flaw allows an attacker with client management permissions to bypass security policies by creating a public client and updating it to a confidential client with weaker authentication, potentially resulting in the persistence of non-compliant clients. This vulnerability has not been actively exploited and affects several Red Hat products.