CVE-2026-23552Disclosure(apache / camel)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 2 mentions (2026-02-19); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-02-19: 2Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-07-21: 1PoC Mentioned / Linked · 2026-07-21: 1Exploit Tool / Code · 2026-07-21: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-07-21: 102-1902-2302-2402-2702-2807-21
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
PoC
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure1Patch1
2026-02-231
Disclosure1
2026-02-241
Patch1
2026-02-271
Disclosure1
2026-02-281
Disclosure1
2026-07-211
PoC1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-25747: Apache Camel: Deserialization of Untrusted Data in Camel LevelDB https://www.openwall.com/lists/oss-security/2026/02/18/6 CVE-2026-23552: Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy https://www.openwall.com/lists/oss-security/2026/02/18/7

    Post summary

    The post announces two new Apache Camel vulnerabilities—deserialization of untrusted data in Camel LevelDB and a cross-realm token acceptance bypass in Camel-Keycloak—providing links to discussion threads for more information.

    00042454
    4.4K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-53913 PT ID: PT-2026-55908 Vendor: Apache Software Foundation Product: Apache Camel Keycloak Description: Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty - validates the roles, and - only if requiredPermissions is non-empty - validates the permissions. The actual cryptographic verification of the bearer access token (signature, issuer and expiry for a local JWT, or active-state and issuer for token introspection) is performed exclusively inside those role and permission checks. KeycloakSecurityPolicy defaults requiredRoles and requiredPermissions to empty - which is the documented 'Basic Setup' - so on a route configured that way the role and permission checks are skipped and the access token is therefore never verified. The token-presence check still rejects a missing token, but an invalid token is accepted: any non-null value in the Authorization: Bearer header - including an arbitrary string or a forged, unsigned JWT - passes the policy and the request reaches the protected route, with no signature, issuer or expiry check and no request to Keycloak. The token is read from the inbound request header because allowTokenFromHeader defaults to true. Because the normal reason to place a route behind this policy is that the route performs server-side work, the bypass results in unauthenticated access to that work; where the protected route forwards to a code-execution-capable producer, it can result in unauthenticated remote code execution. This defect is independent of CVE-2026-23552: that issue concerned the issuer claim and was fixed by adding a check inside the verification routine, but here the verification routine is not reached at all in the default configuration, so the defect remains. This issue affects Apache Camel: from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55908 • https://github.com/oscerd/cve-2026-53913 #dbugs_vuln

    Post summary

    The post reveals that a PoC/exploit for CVE‑2026‑53913 has been published, detailing a token‑verification bypass that could allow unauthenticated remote code execution, with no indication of active exploitation or available patch.

    00030765
    3.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23552 (CVSS:9.1, CRITICAL) is Analyzed. Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak Keyc..https://nvd.nist.gov/vuln/detail/CVE-2026-23552 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-23552 is a critical cross-realm token acceptance bypass vulnerability in the Keycloak SecurityPolicy Apache Camel component, highlighted with a CVSS score of 9.1.

    0000041
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23552 (CVSS:9.1, CRITICAL) is Analyzed. Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak Keyc..https://nvd.nist.gov/vuln/detail/CVE-2026-23552 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑23552, a critical Cross‑Realm Token Acceptance Bypass in the Keycloak Apache Camel component, linking to the NVD entry without providing a PoC, exploit, or patch details.

    0000029
    173 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Apache Camel 4.15.0-4.17.x allows cross-realm token bypass in KeycloakSecurityPolicy, risking tenant isolation. Upgrade to 4.18.0 now! 🔒 https://radar.offseq.com/threat/cve-2026-23552-cwe-346-origin-validation-error-in--099c72c7 #OffSeq #ApacheCamel #infosec https://t.co/Lw4VBRHddb

    Post summary

    The tweet alerts users to a critical Apache Camel vulnerability that enables cross‑realm token bypass in KeycloakSecurityPolicy, urging an upgrade to version 4.18.0 to mitigate tenant isolation risks.

    0000052
    269 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-23552 - Critical Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT... https://www.thehackerwire.com/vulnerability/CVE-2026-23552/ https://t.co/cGAuzsS28P

    Post summary

    A critical vulnerability (CVE-2026-23552) in Apache Camel's Keycloak component allows cross-realm token acceptance due to missing issuer validation. The issue is highlighted in a disclosure article without evidence of active exploitation or available patches.

    0000061
    113 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apache Camel patches critical flaws in Keycloak (CVE-2026-23552) and LevelDB (CVE-2026-25747) components that allow auth bypass and RCE. Update to 4.18.0. #ApacheCamel #CyberSecurity #CVE #InfoSec #Keycloak #JavaSecurity #DevSecOps https://securityonline.info/apache-camel-patches-critical-keycloak-leveldb-flaws/

    Post summary

    Apache Camel has released a patch for two critical flaws (CVE-2026-23552 and CVE-2026-25747) that allow authentication bypass and remote code execution; users should upgrade to version 4.18.0.

    00000171
    10.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more