# Keycloak client policy enforcement flaw

Source: https://startwithidentity.com/cves/cve-2026-18207/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Keycloak did not enforce a client policy the way the realm configuration said it would. Client policies are the control that requires [PKCE](https://startwithidentity.com/glossary/pkce/), blocks implicit flow, or asserts [FAPI](https://startwithidentity.com/glossary/fapi/). A policy that does not fire is a paper control. Red Hat patched in 2026. Keycloak advisories in the same period also document a WebAuthn attestation-policy bypass (`fmt:none`).

## Why it matters

Most Keycloak hard-won lessons live in client policies, not in the default realm. If those policies are skippable, every "we are FAPI-grade" statement in an audit package is wrong.

## What to do

- Upgrade Keycloak to the 2026 build that names CVE-2026-18207.
- Add a test client that violates each policy (no PKCE, implicit, `fmt:none`) and assert it is rejected.
- Read the [OAuth 2.0](https://startwithidentity.com/standards/oauth-2-0/) pitfalls section before you relax a policy to "make a vendor integration work."

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2026-18207](https://nvd.nist.gov/vuln/detail/CVE-2026-18207)
- Red Hat Keycloak advisories, including WebAuthn `fmt:none`
