CCB Alert@CCBalertPatch
The notice highlights high‑severity CVE‑2026‑1486 and CVE‑2026‑1529 in Keycloak/RedHat, warns of low‑privilege impersonation, and directs users to an official patch URL.
CVE@CVEnewDisclosure
Keycloak’s JWT authorization grant flow fails to verify whether an Identity Provider is enabled, potentially allowing unauthorized access.
cvereports@_cvereportsDisclosure
Keycloak’s JWT Authorization Grants implementation contains a logic flaw that allows disabled Identity Providers to issue valid tokens, as explained in the deep‑dive report.
CVEFind.com@CveFindComDisclosure
The text discloses a Keycloak jwt-authorization-grant flow vulnerability that lets attackers generate valid JWT assertions even when the Identity Provider is disabled, resulting in unauthorized access token issuance.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A newly disclosed Keycloak vulnerability (CVE-2026-1486) permits token issuance via a disabled identity provider, but no PoC, exploit, or patch details are provided.
The Hacker Wire@TheHackerWireDisclosure
Keycloak’s jwt‑authorization‑grant flow fails to verify if an Identity Provider is enabled, allowing unauthorized token issuance.