{"id":"CVE-2026-1529","title":"A flaw was found in Keycloak","summary":"A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verifica…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-347","CWE-347"],"published":"2026-02-09","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-1529","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:2363","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2364","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2365","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2366","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-1529","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433783","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:2363","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:2364","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:2365","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:2366","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-1529","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2433783","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1529.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","exploit-available"],"epss":0.00461,"epssPercentile":0.39118,"ingestedAt":"2026-07-03T18:53:52.186Z","exploits":{"github":4,"githubRepos":["https://github.com/ninjazan420/CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation","https://github.com/0x240x23elu/CVE-2026-1529","https://github.com/ackemed/CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation"],"checkedAt":"2026-09-21T15:28:05.042Z"},"exploitAvailable":true,"slug":"CVE-2026-1529","body":"## Overview\n\nA flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":4960,"id":"CVE-2026-1529","ts":1788887220125,"field":"exploit_available","old":"false","new":"true"},{"seq":3843,"id":"CVE-2026-1529","ts":1788886352778,"field":"exploit_available","old":"true","new":"false"},{"seq":2677,"id":"CVE-2026-1529","ts":1788883017910,"field":"exploit_available","old":"false","new":"true"},{"seq":1706,"id":"CVE-2026-1529","ts":1788882422028,"field":"exploit_available","old":"true","new":"false"},{"seq":813,"id":"CVE-2026-1529","ts":1788881855827,"field":"exploit_available","old":"false","new":"true"}]}