Missing Authorization in Keycloak - CVE-2026-18214
Published: July 31, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to the Keycloak realm.
The vulnerability exists due to missing authorization in the token exchange feature when exchanging a Google token. A remote user can exchange a valid Google token from an unapproved domain to gain unauthorized access to the Keycloak realm.
The issue applies to realms configured to restrict access to specific Google Workspace domains.