
CVE-2026-33585 Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user … https://www.cve.org/CVERecord?id=CVE-2026-33585
Post summary
The post announces CVE‑2026‑33585, noting that mismanagement of the idle timeout in Keycloak can allow attackers to impersonate authenticated tenant users, with no PoC, exploit, active hacking evidence, or patch provided.

