Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18208— Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim

CVSS 6.5 · Medium EPSS 0.20% · P10

Affected Version Matrix 6

VendorProductVersion RangeStatus
Red HatRed Hat Build of Keycloakanyaffected
anyaffected
anyaffected
Red HatRed Hat Data Grid 8anyunaffected
Red HatRed Hat JBoss Enterprise Application Platform Expansion Packanyunaffected
Red HatRed Hat Single Sign-On 7anyunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-18208

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Keycloak 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Keycloak是Keycloak组织开源的一种身份和访问管理解决方案。 Keycloak存在授权问题漏洞,该漏洞源于OIDC token introspection端点处理不当,当机密客户端尝试introspect为不同受众发行的令牌时,端点仍返回完整的令牌声明,可能导致未授权客户端绕过受众限制并访问敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Build of Keycloak-cpe:/a:redhat:build_keycloak:
Red HatRed Hat Data Grid 8-cpe:/a:redhat:jboss_data_grid:8
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack-cpe:/a:redhat:jbosseapxp
Red HatRed Hat Single Sign-On 7-cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-18208

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18208

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18208 (2)

Same Patch Batch · Red Hat · 2026-07-31 · 14 CVEs total

CVE-2026-100798.5 HIGHStackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injecti
CVE-2026-181418.2 HIGHAap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http he
CVE-2026-157227.5 HIGH389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_
CVE-2026-117707.5 HIGH389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
CVE-2026-182156.8 MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses co
CVE-2026-182146.8 MEDIUMKeycloak-services: keycloak-services: google external access-token exchange bypasses hoste
CVE-2026-182036.5 MEDIUMKeycloak-services: keycloak-services: group policy extendchildren matches sibling group pa
CVE-2026-161054.9 MEDIUMKeycloak-services: keycloak-services: missing per-role authorization on rolecontainerresou
CVE-2026-182184.2 MEDIUMKeycloak-services: keycloak-services: client not-before revocation ignored when realm not-
CVE-2026-182114.2 MEDIUMKeycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefi
CVE-2026-182063.7 LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching b
CVE-2026-182173.4 LOWKeycloak-services: keycloak-services: saml http-redirect binding response preserves query
CVE-2026-182093.4 LOWKeycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-18208

No comments yet


Leave a comment