Keycloak is a widely used identity provider; this flaw enables full realm admin takeover via DCR, risking org-wide identity and access compromise.
CVE-2026-15572
Keycloak DCR flaw allows escalation to full realm administrator
Is CVE-2026-15572 being exploited?
Not confirmed. CVE-2026-15572 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.36% probability of exploitation in the next 30 days.
How severe is CVE-2026-15572?
CVE-2026-15572 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-15572?
Yes. A fix has been recorded for CVE-2026-15572. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-15572 affect?
CVE-2026-15572 affects Keycloak (Dynamic Client Registration - Allowed Protocol Mapper Types). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-15572?
Apply vendor patch when available or disable DCR; restrict client registration and audit mappers/clients.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Attacker with client-registration rights can escalate to full Keycloak realm admin, modify roles, issue tokens, and seize clients.
Immediate action required