PT-2026-66728 · Red Hat · Keycloak

CVE-2026-18215

·

Published

2026-07-31

·

Updated

2026-08-31

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description Keycloak allows users to authenticate using Microsoft accounts with restrictions limited to a specific organization (tenant). A flaw exists where this tenant restriction is ignored during the token exchange process. This allows an attacker possessing a valid Microsoft token from an unrelated organization to bypass the restriction and gain unauthorized access to the Keycloak realm, which could lead to the exposure of sensitive data or unauthorized actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KEYCLOAK-2026-18215
CVE-2026-18215

Affected Products

Keycloak