PT-2026-20652 · Red Hat+1 · Keycloak+1

Andrea Cosentino

·

Published

2026-02-19

·

Updated

2026-02-28

·

CVE-2026-23552

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Camel versions 4.15.0 through 4.17.9
Description The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. This allows a token issued by one Keycloak realm to be silently accepted by a policy configured for a different realm, which breaks tenant isolation. The iss claim identifies the issuer of the JWT.
Recommendations Upgrade to version 4.18.0 to resolve this issue.

Exploit

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-23552
GHSA-C3F3-CC42-XR9V

Affected Products

Apache Camel
Keycloak