Beveiligingsadvies

CVE-2026-18215

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-31 06:48:14
Laatst bijgewerkt 2026-09-16 18:34:34
Toegewezen door redhat
CVSS-score 6.8
Status PUBLISHED

Beschrijving

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.