CVE-2026-18572
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours).
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- redhat/build of keycloak
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2026-18572Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2509763Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.