Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 80%

CVE-2026-8922: Incorrect Implementation of Authentication Algorithm in Red Hat Red Hat build of Keycloak 26.4

0
Medium
VulnerabilityCVE-2026-8922cvecve-2026-8922
Published: 05/19/2026 (05/19/2026, 06:27:35 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat build of Keycloak 26.4

Description

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens that should have been revoked to remain active, potentially leading to unauthorized access or continued session validity. This could impact the security of systems utilizing Keycloak for identity and access management.

CVSS v3.1

Score 5.4medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 12:21:41 UTC

Technical Analysis

The vulnerability in Red Hat build of Keycloak 26.4 involves incorrect implementation of token revocation policies in the OpenID Connect Introspection feature. Specifically, when both realm-level and client-level 'notBefore' revocation policies are configured, the realm-level policy is not properly honored, allowing tokens that should be revoked to remain active. This could lead to unauthorized access or continued session validity in systems relying on Keycloak for identity and access management. Red Hat's security advisories for Keycloak 26.6.3 include this vulnerability among several others fixed in the updated images. The advisories do not specify a separate patch for this CVE but recommend upgrading to the 26.6.3 release. The vulnerability has a CVSS 3.1 base score of 5.4 (medium severity) with network attack vector, low complexity, requiring low privileges, no user interaction, and impacts confidentiality and integrity.

Potential Impact

Tokens that should have been revoked due to realm-level 'notBefore' policies may remain valid, potentially allowing unauthorized access or continued session validity. This undermines the security of authentication and authorization processes in affected Keycloak deployments. The impact is limited to confidentiality and integrity, with no direct availability impact reported. No known exploits in the wild have been reported.

Mitigation Recommendations

Red Hat has released updated Keycloak 26.6.3 images that address this vulnerability along with other security issues. Users should upgrade to Red Hat build of Keycloak 26.6.3 as provided in the official Red Hat Customer Portal advisories RHSA-2026:25097 and RHSA-2026:25098. Before applying the update, back up existing installations including applications, configuration files, and databases. No separate patch for CVE-2026-8922 alone is provided; remediation is via upgrading to the fixed 26.6.3 version. Monitor Red Hat advisories for any further updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-05-19T06:07:42.943Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-8922","vendor":"Red Hat"}]

Threat ID: 6a0c1307ec166c07b07e0205

Added to database: 05/19/2026, 07:36:39 UTC

Last enriched: 06/26/2026, 12:21:41 UTC

Last updated: 07/31/2026, 19:23:00 UTC

Views: 110

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses