Thehackerwire
CVE-2026-23552: Critical Vulnerability in Keycloak Component
First seen 24 Feb 2026, 18:11 UTC
•
•82% similarity
•62.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
CVE-2026-23552 identifies a critical vulnerability in the KeycloakSecurityPolicy of the Apache Camel Keycloak component. This flaw allows a Cross-Realm Token Acceptance Bypass, where JWT tokens from one Keycloak realm are accepted by a policy configured for a different realm, compromising tenant isolation. Affected users are advised to upgrade to Apache Camel version 4.18.0 to mitigate this issue.
ThreatCluster AI
How this analysis works
Timeline
2026-02-09
First public PoC released
2026-02-23
CVE-2026-23552 published
2026-02-24
Article published detailing the vulnerability