Junglewise Threat Intelligence

CVE-2026-1486: Keycloak improper security check for disabled Identity Providers

CVE-2026-1486 · Severity: high · CVSS 8.8 · Published 2026-02-09

Technologies: Red Hat build of Keycloak, Keycloak. Vendors: Red Hat, Keycloak.

Executive brief

Keycloak, a popular identity and access management solution, contains a flaw where it continues to trust external identity providers even after they have been disabled by an administrator. This means that if a partner organization or login service is removed due to a security breach or offboarding, an attacker with access to that service's credentials could still log into your systems. This could lead to unauthorized access to sensitive data and applications despite administrative attempts to block the connection.

Technical details

A vulnerability exists in the Keycloak jwt-authorization-grant flow due to an improper security check in the issuer lookup mechanism. The 'lookupIdentityProviderFromIssuer' function retrieves IdP configurations but fails to filter for the 'isEnabled=false' status. Consequently, if an administrator disables an IdP (e.g., following a compromise), an attacker possessing that IdP's signing key can still generate valid JWT assertions. Keycloak will accept these assertions and issue valid access tokens, bypassing the intended administrative lockout. The issue is addressed in Red Hat build of Keycloak 26.4.9.

Affected products

  • Red Hat build of Keycloak 26.4.0 through 26.4.8
  • Keycloak Keycloak versions prior to 26.4.9

Timeline

  • 2026-01-27: disclosed: Initial report in Red Hat Bugzilla
  • 2026-02-09: advisory: Red Hat published security advisory RHSA-2026:2365
  • 2026-02-09: patched: Fixed in Red Hat build of Keycloak 26.4.9

References

Related threats