CVE-2026-1529Disclosure

MEDIUMCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 5 mentions (2026-02-10); latest day: 1
  • 12 total mentions across 4 days

Deep dive

Activity timeline12 mentions / 4d
01345Mentions · 2026-02-09: 3Mentions · 2026-02-10: 5Mentions · 2026-02-11: 3Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-11: 1Exploit Tool / Code · 2026-02-10: 1Exploit Tool / Code · 2026-02-11: 1Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-09: 3Technical Details · 2026-02-10: 4Technical Details · 2026-02-11: 102-0902-1002-1109-04
Signal classification5 categories
Disclosure
541.7%
General
325.0%
Patch
216.7%
PoC
18.3%
Exploit
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-093
Disclosure3
2026-02-105
Disclosure1General1Patch2PoC1
2026-02-113
Disclosure1Exploit1General1
2026-09-041
General1
Full discourse12 posts
  • Mehmet INCE@mdisec
    Disclosure

    Keycloak - CVE-2026-1529 An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. https://cvefeed.io/vuln/detail/CVE-2026-1529

    Post summary

    The post details how CVE-2026-1529 allows attackers to alter organizational ID and target email within a JWT payload in Keycloak, without mentioning any PoC, exploit code, active exploitation, or patch.

    562136624540.5K
    33.2K followersView on X
  • _cr0w_@f3dscr0w
    PoC

    Just dropped: CVE-2026-1529 in #Keycloak - and working PoC. Unauthorized user registration via broken invitation token validation. CVE Score 8.1 → Detailed write-up: https://f3ds.vercel.app/posts/cve-2026-1529-keycloak-unauthorized-registration-via-invitation-token/ → PoC on GitHub: https://github.com/ninjazan420/CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation Already testing this? #Keycloak #CVE #PoC

    Post summary

    A working PoC and GitHub repository for CVE‑2026‑1529 have been released, demonstrating unauthorized registration via broken invitation token validation in Keycloak. No active exploitation or patch information is provided.

    20043412
    32 followersView on X
  • Kaan@wkaandemir
    Patch

    Güvenlik Rehberi Güncellemesi: CVE-2026-1529 (Keycloak Organizations) Keycloak tarafındaki kritik zafiyet analizini şablonumuza göre yeniledik. Özetle; organizasyon davet ve kayıt akışındaki action token (JWT) doğrulamasında ciddi bir mantık hatası var. Bu durum, düşük yetkili bir kullanıcının kendi sınırlarını aşarak başka organizasyonlara sızmasına ve veri sızıntısına yol açabiliyor. Ne yapmalı? Hızla güncel sürümlere geçilmeli: 26.2.13, 26.4.9 veya 26.5.0+. Davet kabulü sırasında token içeriği; sunucu tarafındaki kayıtlarla (jti/orgId/email) eşleştirilmeli ve tek seferlik kullanım (OTP) mutlaka zorunlu kılınmalı.

    Post summary

    Keycloak's organization invite flow has a logic flaw in action token validation that could allow low‑privileged users to bypass boundaries and exfiltrate data. Updating to versions 26.2.13, 26.4.9 or later resolves the issue.

    10032383
    1.8K followersView on X
  • Mathieu Passenaud@mathieupassenau
    General

    @hanxhx_ et pas que, tu sais il y a des Keycloak tellement vieux que tu peux retrouver la CVE-2026-1529 ou encore cve-2021-4133

    Post summary

    The tweet only cites two CVE identifiers related to old Keycloak installations, with no further details or actionable information.

    10001320
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-1281 2 - CVE-2026-21509 3 - CVE-2026-21643 4 - CVE-2026-1529 5 - CVE-2025-67813 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post enumerates five trending CVE identifiers without providing additional technical context or actionable information.

    00020283
    1.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High improper security check in #Keycloak #Redhat CVE-2026-1486 CVE-2026-1529 CVSS: 8.8-8.1. A remote attacker with low privileges can gain unauthorized access by impersonating users. Install the official patch: https://bugzilla.redhat.com/show_bug.cgi?id=2433347 #Patch

    Post summary

    This warning alerts users to two high‑severity Keycloak CVEs that allow privilege escalation through improper security checks and directs them to apply the official Red Hat patch for remediation.

    01001221
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1529 Keycloak JWT Invitation Token Validation Bypass Enabling Unauthorized Registration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1529

    Post summary

    The CVE‑2026‑1529 vulnerability allows attackers to bypass JWT invitation token validation in Keycloak, enabling unauthorized registrations.

    00011138
    4.0K followersView on X
  • Kaan@wkaandemir
    General

    https://cvefeed.io/vuln/detail/CVE-2026-1529

    Post summary

    The input contains only a URL to a CVE detail page with no additional context, so no specific indicators can be confirmed.

    10000193
    1.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1529 A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON W… https://www.cve.org/CVERecord?id=CVE-2026-1529

    Post summary

    A newly discovered Keycloak flaw (CVE-2026-1529) allows attackers to alter organization ID and target email in invitation tokens, yet no PoC, exploit code, or active exploitation is reported.

    00010225
    56.5K followersView on X
  • TRONCAL Yannick@ytroncal
    Disclosure

    CVE-2026-1529 http://Org.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validation https://cvefeed.io/vuln/detail/CVE-2026-1529

    Post summary

    The text announces CVE-2026-1529, a Keycloak vulnerability that allows unauthorized organization registration through improper invitation token validation, without any mention of PoC, exploitation, or patches.

    0000063
    127 followersView on X
  • Shailesh Kumavat@KumavatShailesh
    Exploit

    CVE-2026-1529 Keycloak Exploit Tool #keycloak #BugBounty #cve https://github.com/0x240x23elu/CVE-2026-1529

    Post summary

    A GitHub repository is linked that presumably contains an exploit tool for CVE-2026-1529, indicating the availability of functional exploit code.

    00000121
    284 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1529 - High A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. ... https://www.thehackerwire.com/vulnerability/CVE-2026-1529/ https://t.co/fKkGmRIIHZ

    Post summary

    The tweet announces a newly disclosed Keycloak vulnerability (CVE-2026-1529) and explains the exploitation technique involving manipulation of JWT payloads, but it does not provide PoC code, exploit tools, or patch information.

    00000116
    112 followersView on X

Explore more