Логотип exploitDog
bind:CVE-2026-1529
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-1529

Количество 5

Количество 5

redhat логотип

CVE-2026-1529

около 2 месяцев назад

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-1529

около 2 месяцев назад

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-1529

около 2 месяцев назад

A flaw was found in Keycloak. An attacker can exploit this vulnerabili ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-hcvw-475w-8g7p

около 2 месяцев назад

Keycloak affected by improper invitation token validation

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2026-01704

около 2 месяцев назад

Уязвимость компонента JSON Web Token Handler программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-1529

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-1529

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-1529

A flaw was found in Keycloak. An attacker can exploit this vulnerabili ...

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-hcvw-475w-8g7p

Keycloak affected by improper invitation token validation

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-01704

Уязвимость компонента JSON Web Token Handler программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу