Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18572

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to be an authenticated user and the target resource must be specifically protected by a time-based authorization policy. Successful exploitation allows an attacker to bypass temporal access controls and obtain permissions outside of allowed time windows. The vulnerability's root cause is the improper merging of user-supplied claims which allows them to overwrite trusted server-side evaluation attributes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesAffected
Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Affected
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2509763keycloak-services: keycloak-services: UMA claim token can override authorization time-policy evaluation attributes

EPSS

Процентиль: 8%
0.00182
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
15 дней назад

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.

CVSS3: 6.5
debian
15 дней назад

Keycloak provides authorization services that allow administrators to ...

CVSS3: 6.5
github
15 дней назад

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.

EPSS

Процентиль: 8%
0.00182
Низкий

6.5 Medium

CVSS3