CVE-2026-1529: Red Hat Build Of Keycloak 26.2
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.
Affected products
- Red Hat Red Hat Build Of Keycloak 26.2: before 26.2.13-1 (fixed in 26.2.13-1); before 26.2-15 (fixed in 26.2-15)
- Red Hat Red Hat Build Of Keycloak 26.2.13
- Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.9-1 (fixed in 26.4.9-1); before 26.4-11 (fixed in 26.4-11); before 26.4-10 (fixed in 26.4-10)
- Red Hat Red Hat Build Of Keycloak 26.4.9
Published 2026-02-09. Last modified 2026-07-15.