AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-18569

LOW · CVSS 3.7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

A vulnerability exists in the backchannel logout endpoint of the keycloak-services component in the Red Hat Build of Keycloak, specifically when an OIDC identity provider is configured to bypass signature validation. This flaw allows an attacker with knowledge of a user's session details to send unauthorized logout requests, potentially disrupting user sessions. Organizations utilizing Keycloak for authentication and session management should prioritize addressing this issue to mitigate the risk of session disruption.

CVE
CVE-2026-18569
Severity
LOW
CVSS
3.7
EPSS
0.16%

Original NVD Description

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.