Authorization Flaw in Keycloak Allows Bypassing Time-Based Access Restrictions
CVE-2026-18572

6.5MEDIUM

What is CVE-2026-18572?

A vulnerability in Keycloak's authorization services enables users to manipulate time values in their requests. This flaw allows attackers to bypass time-based access restrictions implemented by the system, granting unauthorized access to protected resources even outside of allowed time frames. Administrators relying on these policies for enforcing security can find their systems compromised, as valid time checks no longer prevent access to sensitive resources.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.