CVE-2026-18215

⚪ Do wiadomości

Błąd w Keycloak umożliwia dostęp do danych z innej organizacji przy użyciu tokenu Microsoft.

CVSS
6.8
EPSS
0.2%
Exploit
none
Vendor
redhat
Opis źródłowy (NVD)

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-07-31 08:16:27 UTC
Ostatnia modyfikacja (NVD)2026-09-16 19:17:09 UTC
Referencje