PatchSiren cyber security CVE debrief
CVE-2026-18218 Red Hat CVE debrief
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a 'not-before' policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators and users of Keycloak identity management service should be aware of this vulnerability and take necessary precautions. Affected operators, platform administrators, vulnerability management teams, and security teams should review and update Keycloak configurations to ensure proper token revocation, monitor for unusual token usage patterns, and implement additional authentication mechanisms to mitigate the potential impact of this vulnerability. This may involve coordinating with Keycloak support or security teams to ensure that the necessary patches or mitigations are applied. Additionally, defenders should verify that their Keycloak deployments are not exposed to unauthorized access and that token revocation policies are properly configured. Limited evidence suggests that defenders should focus on verifying Keycloak configurations and monitoring token usage to detect potential exploitation attempts. This requires collaboration between operators, administrators, and security teams to ensure that the necessary precautions are taken to prevent exploitation of this vulnerability. The potential impact of this vulnerability on affected systems and data could be significant if not properly mitigated. Therefore, it is essential that all stakeholders take immediate action to review and update their Keycloak configurations and implement additional security measures to prevent exploitation. This may involve conducting a thorough review of Keycloak deployments, identifying potential vulnerabilities, and implementing compensating controls to mitigate the risk of exploitation. By taking these precautions, defenders can reduce the risk of exploitation and protect their Keycloak deployments from potential attacks. Limited evidence suggests that defenders should prioritize verifying Keycloak configurations and monitoring token usage to detect potential exploitation attempts. This requires a coordinated effort between operators, administrators, and security teams to ensure that the necessary precautions are taken to prevent exploitation of this vulnerability. The vulnerability highlights the importance of proper token revocation policies and configuration in Keyc
Technical summary
The vulnerability lies in the TokenManager component of Keycloak. When an administrator attempts to revoke tokens for a specific application using a 'not-before' policy, the revocation may be ignored if an older revocation policy exists in the security realm. This could allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. The technical impact of this vulnerability is that it could allow unauthorized access to user information and sessions.
Defensive priority
Medium priority due to potential for token revocation bypass.
Recommended defensive actions
- Review and update Keycloak configurations to ensure proper token revocation.
- Monitor for unusual token usage patterns.
- Implement additional authentication mechanisms.
- Confirm whether affected Keycloak deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The evidence from Redhat indicates a flaw in Keycloak's TokenManager component. Further details are limited. The administrator attempts to revoke tokens for a specific application (client) using a 'not-before' policy may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This could allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. Limited evidence suggests that defenders should verify Keycloak configurations, monitor token usage, and implement additional authentication mechanisms.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:28.177Z and has not been modified since then.