PULSE
LIVE62signals / 24h
FEED
← All CVEs
CVE WatchAug 5, 2026

CVE-2026-15573

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatche

CVSS

8.1

High

EPSS

KEV

Exploit Today

0-100

Published: Aug 5, 2026 · Last modified: Aug 5, 2026

EPSS · 30d

Not enough EPSS history yet.

Technical description

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into applying a less restrictive security policy than intended. This allows an authenticated user to access administrative or restricted areas they should not have permission to see.

Official references
Related CVEs

No related CVEs by CWE or product.