Improper Authentication in Keycloak - CVE-2026-18215
Published: July 31, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to the Keycloak realm.
The vulnerability exists due to improper authentication in the Microsoft identity provider tenant restriction handling when using the token exchange feature. A remote user can exchange a valid Microsoft token issued by a different organization to gain unauthorized access to the Keycloak realm.
The issue can potentially expose sensitive data or permit unauthorized actions.