Intel

AIKIDO-2026-201368

keycloak-services is vulnerable to Improper Access Control

Improper Access ControlCVE-2026-1609 Published Yesterday

81

High Risk

This Affects:

JAVAkeycloak-services
26.5.0 - 26.5.2
Fixed in 26.5.3
Are you affected? Scan for Free

TL;DR

When the JWT authorization grant preview feature is enabled, keycloak-services issues tokens through the grant without checking whether the resolved user account is enabled. A user whose account has been disabled continues to obtain access and refresh tokens through the JWT authorization grant. The grant processing associates the resolved user with the token-issuing event and proceeds straight to issuance with no enabled-status or required-actions gate. The fix rejects disabled users and accounts with pending required actions before any token is issued.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have enabled the JWT authorization grant preview feature.

Background info

keycloak-services is vulnerable to Improper Access Control in versions 26.5.0 - 26.5.2.

How to fix this

Upgrade the org.keycloak:keycloak-services library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform