CVE-2026-1486Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-358

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-02-10)
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-02-09: 2Mentions · 2026-02-10: 4Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-10: 402-0902-10
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-092
Disclosure2
2026-02-104
Disclosure3Patch1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: High improper security check in #Keycloak #Redhat CVE-2026-1486 CVE-2026-1529 CVSS: 8.8-8.1. A remote attacker with low privileges can gain unauthorized access by impersonating users. Install the official patch: https://bugzilla.redhat.com/show_bug.cgi?id=2433347 #Patch

    Post summary

    The notice highlights high‑severity CVE‑2026‑1486 and CVE‑2026‑1529 in Keycloak/RedHat, warns of low‑privilege impersonation, and directs users to an official patch URL.

    01001221
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1486 A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled befor… https://www.cve.org/CVERecord?id=CVE-2026-1486

    Post summary

    Keycloak’s JWT authorization grant flow fails to verify whether an Identity Provider is enabled, potentially allowing unauthorized access.

    00010153
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-1486: Zombie IdPs: The Keycloak CVE-2026-1486 Deep Dive A critical logic flaw in Keycloak's implementation of JWT Authorization Grants allows disabled Identity Providers (IdPs) to continue issuing valid access tokens. By failing to check the ... https://cvereports.com/reports/CVE-2026-1486

    Post summary

    Keycloak’s JWT Authorization Grants implementation contains a logic flaw that allows disabled Identity Providers to issue valid tokens, as explained in the deep‑dive report.

    0000061
    27 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1486: HIGH] Keycloak vulnerability in jwt-authorization-grant flow lets attackers generate valid JWT assertions with disabled Identity Provider, leading to unauthorized access token issuance. Update ...#cve,CVE-2026-1486,#cybersecurity https://cvefind.com/CVE-2026-1486

    Post summary

    The text discloses a Keycloak jwt-authorization-grant flow vulnerability that lets attackers generate valid JWT assertions even when the Identity Provider is disabled, resulting in unauthorized access token issuance.

    0000081
    583 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1486 Keycloak JWT Authorization Grant Vulnerability Allows Token Issuance via Disabled IdP https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1486

    Post summary

    A newly disclosed Keycloak vulnerability (CVE-2026-1486) permits token issuance via a disabled identity provider, but no PoC, exploit, or patch details are provided.

    0000067
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1486 - High A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The is... https://www.thehackerwire.com/vulnerability/CVE-2026-1486/ https://t.co/KnljCyM1Gk

    Post summary

    Keycloak’s jwt‑authorization‑grant flow fails to verify if an Identity Provider is enabled, allowing unauthorized token issuance.

    0000054
    112 followersView on X

Explore more