Junglewise Threat Intelligence

CVE-2026-11800: Keycloak JWT algorithm confusion in JWT Authorization Grant flow

CVE-2026-11800 · Severity: high · CVSS 8.1 · Published 2026-06-25

Technologies: Red Hat build of Keycloak, Red Hat build of Keycloak, Keycloak. Vendors: Red Hat, Keycloak.

Executive brief

A security vulnerability has been identified in Keycloak, a popular identity and access management solution used to secure web and mobile applications. An attacker with valid client credentials can exploit a flaw in how the system verifies digital signatures to impersonate other users. This could allow an unauthorized person to gain access to sensitive data or take over administrative accounts within the organization.

Technical details

A JWT algorithm confusion vulnerability exists in Keycloak within the JWT Authorization Grant flow. The flaw resides in the improper verification of cryptographic signatures (CWE-347), where the system may be coerced into using an unintended algorithm for validation. An attacker possessing valid client credentials can forge a JWT assertion to bypass signature verification. This allows for the creation of unauthorized access tokens and the impersonation of any federated user linked to the affected Identity Provider. The vulnerability is remediated in Red Hat build of Keycloak 26.6.4-2 and related container images.

Affected products

  • Red Hat Red Hat build of Keycloak < 26.6.4-2
  • Keycloak Keycloak Affected versions prior to 26.6.4-2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory
  • 2026-06-25: patched

References

Related threats