CVE-2026-8922
Last modified
CVE-2026-8922 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens that should have been revoked to remain active, potentially leading to unauthorized access or continued session validity. This could impact the security of systems utilizing Keycloak for identity and access management.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | All versions |
References
- https://access.redhat.com/security/cve/CVE-2026-8922Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2479586Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-8922?
How severe is CVE-2026-8922?
How do I fix CVE-2026-8922?
Are you affected by CVE-2026-8922?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
