CVE-2026-1529: Red Hat Build Of Keycloak 26.2

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

Affected products

  • Red Hat Red Hat Build Of Keycloak 26.2: before 26.2.13-1 (fixed in 26.2.13-1); before 26.2-15 (fixed in 26.2-15)
  • Red Hat Red Hat Build Of Keycloak 26.2.13
  • Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.9-1 (fixed in 26.4.9-1); before 26.4-11 (fixed in 26.4-11); before 26.4-10 (fixed in 26.4-10)
  • Red Hat Red Hat Build Of Keycloak 26.4.9

Published 2026-02-09. Last modified 2026-07-15.