CVE-2026-18572 vulnerability in Red Hat Products
Published on August 2, 2026
Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
Vulnerability Analysis
CVE-2026-18572 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-18572 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18572
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.