Upwind Security MDR[verified]@UpwindMDRDisclosure
The advisory announces CVE-2026-11800, describing a JWT algorithm confusion flaw that lets attackers mint unauthorized access tokens via the Keycloak grant flow, with no patch or PoC and no evidence of active exploitation.
X@intraairPatch
The tweet announces that Keycloak's CVE‑2026‑11800, an algorithm confusion vulnerability allowing forged JWTs, has been patched.
CVE@CVEnewDisclosure
The post announces a JWT algorithm confusion flaw in Keycloak’s JWT Authorization Grant flow, describing how attackers with valid client credentials could bypass security, but provides no PoC, exploit details, patch, or evidence of active exploitation.
Cyber Threat Observatory | Alan Turing Institute@TuringCyberObsDisclosure
The report announces a JWT algorithm confusion flaw in Red Keycloak that could turn identity federation into an access‑control risk, but it provides no PoC, exploit, or patch details.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces a newly discovered Keycloak vulnerability involving JWT algorithm confusion, providing basic technical details but no PoC, exploit code, patch, or evidence of active exploitation.