Missing Authorization Affecting org.keycloak:keycloak-services package, versions [0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGKEYCLOAK-19006721
  • published20 Aug 2026
  • disclosed28 Jul 2026
  • creditUnknown

Introduced: 28 Jul 2026

NewCVE-2026-18201  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

org.keycloak:keycloak-services is an open source identity and access management solution for modern applications and services.

Affected versions of this package are vulnerable to Missing Authorization through the generic identity-provider creation and update paths in IdentityProvidersResource and IdentityProviderResource. An attacker can link or update an identity provider for an organization by sending an organizationId and organization-specific config in the administrative API request. This lets an administrator with only identity-provider management permission influence which organizations use that provider, affecting how users authenticate into those organizations and allowing unauthorized control over organization login routing.

CVSS Base Scores

version 4.0
version 3.1