Logout Exploit in Keycloak Services by Red Hat
CVE-2026-18569

3.7LOW

What is CVE-2026-18569?

A security flaw in the logout endpoint of the keycloak-services component allows unauthorized logout actions. When using an OIDC identity provider that skips signature validation, attackers can exploit this vulnerability to send crafted logout requests without a cryptographic signature. By leveraging knowledge of a user's session parameters, malicious actors can force logout, causing disruption and potentially compromising user experience. It is crucial for organizations using affected Keycloak versions to review their configuration and apply recommended updates to mitigate this vulnerability.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.