CVE-2026-18569
Last modified
CVE-2026-18569 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | All versions |
References
- https://access.redhat.com/security/cve/CVE-2026-18569Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2509755Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-18569?
How severe is CVE-2026-18569?
How do I fix CVE-2026-18569?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18531IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a…5.3
- CVE-2026-18536Data::Entropy versions before 0.010 for Perl read remote ent…7.5
- CVE-2026-1854The Post Flagger plugin for WordPress is vulnerable to Store…6.4
- CVE-2026-18556Authentication bypass using an alternate path or channel vul…7.4
- CVE-2026-1856The Appointment Booking Calendar plugin for WordPress is vul…6.4
- CVE-2026-18568XML::Sig versions from 0.29 before 0.72 for Perl allow signa…7.5
- CVE-2026-1857The Gutenberg Blocks with AI by Kadence WP plugin for WordPr…4.3
- CVE-2026-18570A flaw was found in the full-scope-disabled client-policy ex…5.4
- CVE-2026-18571A flaw was found in the user creation component of Keycloak …7.2
- CVE-2026-18572Keycloak provides authorization services that allow administ…6.5
- CVE-2026-18573A flaw was found in the keycloak-services component of Keycl…6.5
- CVE-2026-18574An authentication bypass vulnerability in Check Point Securi…9.3
Are you affected by CVE-2026-18569?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
