CVE Vulnerabilities

CVE-2026-8922

Incorrect Implementation of Authentication Algorithm

Published: May 19, 2026 | Modified: Jun 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw was found in Keycloak. When both realm-level and client-level notBefore revocation policies are configured, Keycloaks OpenID Connect (OIDC) Introspection feature fails to properly honor the realm-level policy. This allows tokens that should have been revoked to remain active, potentially leading to unauthorized access or continued session validity. This could impact the security of systems utilizing Keycloak for identity and access management.

Weakness

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Affected Software

NameVendorStart VersionEnd Version
Build_of_keycloakRedhat- (including)- (including)
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-operator-bundle:26.4.13-1*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9:26.4-19*
Red Hat build of Keycloak 26.4RedHatrhbk/keycloak-rhel9-operator:26.4-19*
Red Hat build of Keycloak 26.4.13RedHatrhbk/keycloak-rhel9-operator*
Red Hat build of Keycloak 26.6RedHatrhbk/keycloak-operator-bundle:26.6.3-3*
Red Hat build of Keycloak 26.6RedHatrhbk/keycloak-rhel9:26.6-6*
Red Hat build of Keycloak 26.6RedHatrhbk/keycloak-rhel9-operator:26.6-6*
Red Hat build of Keycloak 26.6.3RedHatrhbk/keycloak-rhel9-operator*

References