PatchSiren cyber security CVE debrief
CVE-2026-18208 Red Hat CVE debrief
A flaw in the Keycloak OIDC token introspection endpoint allows unauthorized clients to access sensitive information in tokens issued for different audiences. The endpoint correctly identifies tokens as inactive for certain clients but returns full token claims within a signed JWT field. This issue arises when confidential clients configured for signed JWT introspection responses attempt to introspect tokens issued for different audiences. Administrators of Keycloak instances, security teams responsible for access management and token security, and developers using Keycloak for authentication and authorization should review configurations and ensure audience-based restrictions are properly implemented. Security teams should monitor for suspicious token introspection requests and verify Keycloak deployment integrity. Those responsible for vulnerability management and security operations should prioritize affected system reviews and coordinate with vendors for remediation if necessary. IT asset owners and operators using Keycloak for authentication should assess exposure and take defensive measures. Security teams should consider compensating controls for exposed systems while remediation is scheduled and verified. Those managing change windows and rollback processes should prepare for Keycloak configuration updates. Incident response teams should track exceptions and retest remediated assets to ensure thorough mitigation of the vulnerability.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators of Keycloak instances, security teams responsible for access management and token security, and developers using Keycloak for authentication and authorization should review their configurations and ensure that audience-based restrictions are properly implemented. Additionally, security teams should monitor for suspicious token introspection requests and verify the integrity of their Keycloak deployments. Those responsible for vulnerability management and security operations should prioritize the review of affected systems and coordinate with vendors for remediation efforts if necessary. IT asset owners and operators using Keycloak for authentication should assess their exposure and take appropriate defensive measures. Security teams should also consider compensating controls for exposed systems while remediation is scheduled and verified. Those managing change windows and rollback processes should prepare for potential updates to Keycloak configurations. Finally, incident response teams should be prepared to track exceptions and retest remediated assets to ensure thorough mitigation of the vulnerability. Security teams should also review relevant monitoring, detection, and logs for exposed assets that need extra review to identify potential security incidents related to this vulnerability. Those responsible for source tracking and vulnerability management should closely monitor updates from Keycloak and related sources to stay informed about the vulnerability status and remediation efforts. Security operations teams should prioritize the verification of affected systems and the implementation of defensive measures to mitigate potential security risks associated with this vulnerability. Keycloak administrators should confirm whether affected product deployments exist in their managed environments and assign an owner for follow-up on remediation efforts. Security teams should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Those managing asset inventories should ensure that all Keycloak instances are accounted for and prioritized for review. In summary, a broad range of stakeholders, from
Technical summary
A flaw in the Keycloak OIDC token introspection endpoint allows an unauthorized client to access sensitive information contained in a token issued for a different audience. The endpoint correctly identifies the token as inactive for that client but still returns the full set of token claims within a signed JWT field. This issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience.
Defensive priority
Medium-priority defensive review recommended due to potential unauthorized access to sensitive token information.
Recommended defensive actions
- Review Keycloak configurations and update to the latest version if vulnerable
- Restrict access to OIDC token introspection endpoint
- Monitor for suspicious token introspection requests
- Verify audience-based restrictions are properly implemented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
Evidence from the NVD and Red Hat sources indicates a flaw in the OIDC token introspection endpoint of Keycloak, allowing unauthorized clients to access sensitive token information. Further review of affected systems and vendor remediation status is needed. The CVE record was published on 2026-07-31T08:16:27.323Z and has not been modified since then. Keycloak instances may be affected, and defenders should verify the vulnerability status of their deployments.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:27.323Z and has not been modified since then.