PT-2026-20652 · Red Hat+1 · Keycloak+1
Andrea Cosentino
·
Published
2026-02-19
·
Updated
2026-02-28
·
CVE-2026-23552
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Camel versions 4.15.0 through 4.17.9
Description
The Camel-Keycloak KeycloakSecurityPolicy does not validate the
iss (issuer) claim of JWT tokens against the configured realm. This allows a token issued by one Keycloak realm to be silently accepted by a policy configured for a different realm, which breaks tenant isolation. The iss claim identifies the issuer of the JWT.Recommendations
Upgrade to version 4.18.0 to resolve this issue.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Camel
Keycloak