CVE-2026-1609High· 8.1▾ TwilightA flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
0.5% → 0.6%
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.
build_of_keycloak = 26.5.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-16102High· 8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution
CVE-2026-3429Medium· 4.2A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions
CVE-2026-16072Medium· 4.9A flaw was found in the organization management component of Keycloak
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
CVE-2026-17059Medium· 6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution
CVE-2026-9796Medium· 6.5A flaw was found in Keycloak