Missing Authorization in Keycloak - CVE-2026-18218
Published: July 31, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to retain access to user information and refresh sessions using previously issued tokens.
The vulnerability exists due to missing authorization in the TokenManager component when processing client-specific \"not-before\" token revocation policies. A remote user can continue using previously issued tokens after an administrator attempts to invalidate them to retain access to user information and refresh sessions.
The issue occurs when the security realm already has an older, non-zero revocation policy in place.