Improperly implemented security check for standard in Keycloak - CVE-2026-1486
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to obtain valid access tokens.
The vulnerability exists due to an improperly implemented security check in the jwt-authorization-grant flow when processing JWT assertions from a disabled Identity Provider. A remote user can submit a valid JWT assertion signed with the disabled Identity Provider\'s signing key to obtain valid access tokens.
The issuer lookup mechanism does not filter Identity Provider configurations with isEnabled=false.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-1486
Red Hat build of Keycloak - update to 26.4.9