Incorrect Implementation of Authentication Algorithm in Keycloak - CVE-2026-8922
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access.
The vulnerability exists due to an incorrect implementation of an authentication algorithm in the OpenID Connect introspection feature when both realm-level and client-level notBefore revocation policies are configured. A remote user can submit a token that should have been revoked for introspection to gain unauthorized access.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-8922
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3