Missing Authorization in Keycloak - CVE-2026-18214

 

Missing Authorization in Keycloak - CVE-2026-18214

Published: July 31, 2026 / Updated: September 5, 2026


Vulnerability identifier: #VU146977
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18214
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to the Keycloak realm.

The vulnerability exists due to missing authorization in the token exchange feature when exchanging a Google token. A remote user can exchange a valid Google token from an unapproved domain to gain unauthorized access to the Keycloak realm.

The issue applies to realms configured to restrict access to specific Google Workspace domains.


Affected software

Keycloak

How to mitigate CVE-2026-18214

Install security update from vendor's website.

Keycloak - update to 26.7.3

External References

Related Security Bulletins