Authorization Flaw in Keycloak Allows Bypassing Time-Based Access Restrictions
CVE-2026-18572
6.5MEDIUM
What is CVE-2026-18572?
A vulnerability in Keycloak's authorization services enables users to manipulate time values in their requests. This flaw allows attackers to bypass time-based access restrictions implemented by the system, granting unauthorized access to protected resources even outside of allowed time frames. Administrators relying on these policies for enforcing security can find their systems compromised, as valid time checks no longer prevent access to sensitive resources.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.