Skip to content
CVE-2026-23552: Critical Vulnerability in Keycloak Component

CVE-2026-23552: Critical Vulnerability in Keycloak Component

First seen 24 Feb 2026, 18:11 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

CVE-2026-23552 identifies a critical vulnerability in the KeycloakSecurityPolicy of the Apache Camel Keycloak component. This flaw allows a Cross-Realm Token Acceptance Bypass, where JWT tokens from one Keycloak realm are accepted by a policy configured for a different realm, compromising tenant isolation. Affected users are advised to upgrade to Apache Camel version 4.18.0 to mitigate this issue.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 190d ago How this analysis works

Timeline

2026-02-09
First public PoC released
2026-02-23
CVE-2026-23552 published
2026-02-24
Article published detailing the vulnerability

More articles in this cluster (2)

Following this threat?

Track CVE-2026-23552 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed