Improper Authentication in Keycloak - CVE-2026-18215

 

Improper Authentication in Keycloak - CVE-2026-18215

Published: July 31, 2026 / Updated: September 5, 2026


Vulnerability identifier: #VU146974
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18215
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to the Keycloak realm.

The vulnerability exists due to improper authentication in the Microsoft identity provider tenant restriction handling when using the token exchange feature. A remote user can exchange a valid Microsoft token issued by a different organization to gain unauthorized access to the Keycloak realm.

The issue can potentially expose sensitive data or permit unauthorized actions.


Affected software

Keycloak

How to mitigate CVE-2026-18215

Install security update from vendor's website.

Keycloak - update to 26.7.3

External References

Related Security Bulletins