Token Revocation Flaw in Keycloak Identity Management Service
CVE-2026-18218

4.2MEDIUM

What is CVE-2026-18218?

A flaw exists in the TokenManager component of Keycloak, which may lead to ineffective token revocation under certain conditions. When an administrator attempts to revoke tokens for an application using a 'not-before' policy, the revocation could be ignored if there is an existing, older revocation policy in place for the security realm. This situation allows previously granted tokens to remain active, potentially allowing unauthorized session refreshes and access to user information despite administrative efforts to invalidate them.

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.