CyberRota
← Ana sayfaya dön

CVE-2026-18215

MEDIUM · CVSS 6.8

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-31T08:16:27.893 · Çekilme zamanı: 2026-07-31T12:07:48.819182+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-18215
Severity
MEDIUM
CVSS
6.8
EPSS
Yok
Microsoft Exchange

Orijinal NVD Açıklaması

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.