SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18572

MEDIUM · CVSS 6.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

Keycloak's authorization services are vulnerable to a flaw that permits users to manipulate time values in their authorization requests, effectively bypassing time-based access restrictions. This could lead to unauthorized access to protected resources outside of designated hours. Organizations utilizing Keycloak for access control should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-18572
Severity
MEDIUM
CVSS
6.5
EPSS
0.18%

Original NVD Description

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.

Related CVEs

Other vulnerabilities affecting the same vendor(s)