CVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

History

16 Sep 2026, 16:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:68277 -
  • () https://access.redhat.com/errata/RHSA-2026:68278 -

Information

Published : 2026-07-31 08:16

Updated : 2026-09-16 16:17


NVD link : CVE-2026-18214

Mitre link : CVE-2026-18214

CVE.ORG link : CVE-2026-18214


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-862

Missing Authorization