Improper Verification of Cryptographic Signature in Keycloak - CVE-2026-1529
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to an organization.
The vulnerability exists due to improper verification of cryptographic signatures in Keycloak invitation token validation when processing a modified invitation token JSON Web Token payload. A remote user can modify the organization ID and target email in a legitimate invitation token to gain unauthorized access to an organization.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-1529
Red Hat build of Keycloak - addressed in versions 26.2.13, 26.4.9