Junglewise Threat Intelligence

CVE-2026-8922: Keycloak incorrect revocation policy enforcement in OIDC Introspection

CVE-2026-8922 · Severity: medium · CVSS 5.4 · Published 2026-05-19

Technologies: org.keycloak:keycloak-services (Maven), Keycloak. Vendors: Maven, Keycloak.

Executive brief

A security flaw in Keycloak, a popular identity and access management tool, can allow revoked user tokens to remain active. This occurs when specific revocation policies are set at both the organizational (realm) and application (client) levels simultaneously. As a result, a user whose access should have been terminated could potentially continue to access protected systems and data.

Technical details

A vulnerability was identified in Keycloak's OpenID Connect (OIDC) Introspection feature (CWE-303). When both realm-level and client-level 'notBefore' revocation policies are configured, the introspection endpoint fails to correctly validate the realm-level policy. This logic error allows tokens issued before the realm-level revocation timestamp to be incorrectly treated as active if a client-level policy is also present. An attacker with a previously issued (but theoretically revoked) token could maintain unauthorized session validity. The issue affects versions up to and including 26.6.2 and is addressed in subsequent releases.

Affected products

  • Keycloak Keycloak <= 26.6.2

Timeline

  • 2026-05-18: disclosed: Initial report in Red Hat Bugzilla
  • 2026-05-19: advisory: GitHub Advisory and NVD publication

References

Related threats