CVE-2020-27838 refers to a flaw discovered in the client registration endpoint of Keycloak, an open-source identity and access management (IAM) solution. This endpoint allows developers to register new client applications within a Keycloak server. The vulnerability arises because, in Keycloak versions before 13.0.0, the client registration endpoint lacked proper authentication for fetching information about public clients.