CVE-2026-11800Disclosure(redhat / build_of_keycloak)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to impersonate any federated user linked to the affected Identity Provider, leading to unauthorized access and potential privilege escalation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
build_of_keycloak

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-26: 2Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 2Technical Details · 2026-07-02: 106-2506-2607-02
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure2
2026-06-262
Disclosure2
2026-07-021
Patch1
Full discourse5 posts
  • X@intraair
    Patch

    I told Keycloak how to verify the token. It listened :) CVE-2026-11800: algorithm confusion in the JWT Authorization Grant flow. Forge an assertion, become any federated user. Patched. https://access.redhat.com/security/cve/cve-2026-11800

    Post summary

    The tweet announces that Keycloak's CVE‑2026‑11800, an algorithm confusion vulnerability allowing forged JWTs, has been patched.

    00060358
    211 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-11800 A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypas… https://www.cve.org/CVERecord?id=CVE-2026-11800

    Post summary

    The post announces a JWT algorithm confusion flaw in Keycloak’s JWT Authorization Grant flow, describing how attackers with valid client credentials could bypass security, but provides no PoC, exploit details, patch, or evidence of active exploitation.

    00020747
    58.0K followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-11800 Red Hat Keycloak A JWT algorithm confusion flaw can enable turning identity federation into an access-control risk Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-06-25/TIER_2_CVE-2026-11800.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    The report announces a JWT algorithm confusion flaw in Red Keycloak that could turn identity federation into an access‑control risk, but it provides no PoC, exploit, or patch details.

    0000043
    55 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Keycloak JWT algorithm confusion lets attackers mint unauthorized tokens (CVE-2026-11800) A JWT algorithm confusion flaw impacts Keycloak’s JWT Authorization Grant flow, allowing crafted JWT assertions to bypass signature verification during token issuance. The root cause is improper JWT algorithm handling/validation (algorithm confusion) leading to signature verification being skipped or performed incorrectly. An attacker with valid client credentials can exploit this by submitting a forged assertion via the grant flow to mint access tokens without a valid signature, under conditions where JWT auth grants and a federated IdP linkage are in use. Real-world impact includes unauthorized access token issuance, impersonation of federated users tied to the affected identity provider, and resulting privilege escalation across protected applications and APIs. 👉 Affected: Keycloak; rhbk/keycloak-operator-bundle; rhbk/keycloak-rhel9; rhbk/keycloak-rhel9-operator; rhbk-openshift-rhel9/rhbk-openshift-rhel9 | No fix yet - treat as suspicious

    Post summary

    The advisory announces CVE-2026-11800, describing a JWT algorithm confusion flaw that lets attackers mint unauthorized access tokens via the Keycloak grant flow, with no patch or PoC and no evidence of active exploitation.

    00000100
    231 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-11800 A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypas… https://www.cve.org/CVERecord?id=CVE-2026-11800 ----- Traducción: CVE-2026-11800 Se … http://infoflow.cloud`

    Post summary

    The tweet announces a newly discovered Keycloak vulnerability involving JWT algorithm confusion, providing basic technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more