PT-2026-41841 · Red Hat · Keycloak

·

CVE-2026-8922

·

Published

2026-05-19

·

Updated

2026-07-23

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw in the OpenID Connect (OIDC) Introspection feature occurs when both realm-level and client-level notBefore revocation policies are configured. In this scenario, the system fails to properly honor the realm-level policy, allowing tokens that should have been revoked to remain active. This can lead to unauthorized access or continued session validity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8922
GHSA-83C4-FFJP-MXP9

Affected Products

Keycloak