PT-2026-60351 · Red Hat · Keycloak

CVE-2026-1609

·

Published

2026-07-16

·

Updated

2026-08-09

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description An improper access control issue exists when the JSON Web Token (JWT) authorization grant preview feature is enabled. Keycloak fails to validate the disabled status of a user account during the processing of a JWT authorization grant. A remote attacker with low privileges can present a valid assertion token from an external identity provider to obtain a JWT for a disabled user, enabling unauthorized access to sensitive resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1609

Affected Products

Keycloak