LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-11800

redhat · build of keycloak

Published
CVSS8.1
Severityhigh
WeaknessCWE-347
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-11800

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-11800.