PT-2026-66728 · Red Hat · Keycloak
CVE-2026-18215
·
Published
2026-07-31
·
Updated
2026-08-31
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
Keycloak allows users to authenticate using Microsoft accounts with restrictions limited to a specific organization (tenant). A flaw exists where this tenant restriction is ignored during the token exchange process. This allows an attacker possessing a valid Microsoft token from an unrelated organization to bypass the restriction and gain unauthorized access to the Keycloak realm, which could lead to the exposure of sensitive data or unauthorized actions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak