CVE-2026-18208Medium· 6.5▾ SunlitA flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a con…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token.
build_of_keycloakRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-16106Medium· 4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management
CVE-2026-18218Medium· 4.2A flaw was found in the TokenManager component of the Keycloak identity management service
CVE-2026-16105Medium· 4.9A flaw was found in the RoleContainerResource component of Keycloak
CVE-2026-18201Medium· 5.5Keycloak provides a way to manage identity providers and organizations through its administrative API
CVE-2026-18573Medium· 6.5A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows
CVE-2026-18571Medium· 6.6A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled