Junglewise Threat Intelligence

CVE-2026-1529: Keycloak improper signature verification in organization invitations

CVE-2026-1529 · Severity: high · CVSS 8.1 · Published 2026-02-09

Technologies: Red Hat build of Keycloak. Vendors: Red Hat.

Executive brief

Keycloak, a popular identity and access management tool, contains a security flaw in how it handles organization invitations. An attacker can modify a legitimate invitation to gain unauthorized access to organizations they were not invited to. This could allow unauthorized users to register themselves within sensitive corporate environments, potentially leading to data exposure or further unauthorized actions.

Technical details

A vulnerability exists in Keycloak due to improper verification of cryptographic signatures (CWE-347) within JSON Web Token (JWT) payloads used for organization invitations. An attacker with a legitimate invitation token can modify the organization ID and target email address within the payload. Because the system fails to properly validate the signature after these modifications, the attacker can successfully self-register into an unauthorized organization. This flaw requires network access and low-level authentication (possession of a valid token) to exploit. Red Hat has released patches in versions 26.2.13 and 26.4.9 to address this issue.

Affected products

  • Red Hat Red Hat build of Keycloak 26.2, 26.4, versions prior to 26.2.13 and 26.4.9

Timeline

  • 2026-02-09: disclosed
  • 2026-02-09: patched: Fixed in Red Hat build of Keycloak 26.2.13 and 26.4.9

References

Related threats