Incorrect Authorization Affecting org.keycloak:keycloak-authz-policy-common package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-18752113
  • published13 Aug 2026
  • disclosed28 Jul 2026
  • creditPaul Bottinelli

Introduced: 28 Jul 2026

NewCVE-2026-18203  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

org.keycloak:keycloak-authz-policy-common is a KeyCloak AuthZ: Common Policy Providers

Affected versions of this package are vulnerable to Incorrect Authorization in GroupPolicyProvider in the authorization policy provider. An attacker can bypass extendChildren group-based access checks by joining a different group whose path shares the same text prefix as the protected group, causing unauthorized access to administrative functions or protected resources. The flaw affects authorization decisions for group policies that extend permissions to child groups, where a raw prefix match can treat a sibling group as a valid member of the protected subtree. This lets a user satisfy a policy without belonging to the intended group hierarchy, breaking access control for affected realms and resources.

CVSS Base Scores

version 4.0
version 3.1