CVE-2026-18218: Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero

Published Jul 29, 2026
·
Updated

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Other sources

A flaw was found in the TokenManager.NotBeforeCheck logic within keycloak-services. The vulnerability occurs when a realm has a nonzero not-before timestamp (e.g., from a previous global revocation or import) and an administrator subsequently sets a newer client-specific not-before timestamp to revoke tokens for a single client. Due to a logic error in how these policies are compared (incorrectly prioritizing the older realm-level value or failing to evaluate the newer client-level value), the client-level revocation is ignored. An authenticated attacker holding OIDC tokens (access or refresh) issued after the realm not-before but before the client not-before can continue to use these tokens. Specifically, an attacker can successfully perform token refresh requests, receive an active status from the introspection endpoint, and retrieve user claims from the UserInfo endpoint, bypassing the intended revocation. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Red Hat

Affected Software

2 affected components
keycloak-services
redhat Build Of Keycloak

Event History

Jul 29, 2026
Data Sourced
via Red Hat·09:01 AM
DescriptionSeverityAffected Software
Jul 31, 2026
CVE Published
via MITRE·06:38 AM
Data Sourced
via MITRE·06:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-18218?

CVE-2026-18218 has a medium severity rating of 4.2.

2

How do I fix CVE-2026-18218?

To fix CVE-2026-18218, upgrade to the latest version of Keycloak that addresses this vulnerability.

3

What does CVE-2026-18218 involve?

CVE-2026-18218 involves a flaw in the TokenManager where token revocation for a specific client may be ignored based on the realm's not-before policy.

4

What are the potential impacts of CVE-2026-18218?

The potential impacts of CVE-2026-18218 include unauthorized access due to ineffective token revocation.

5

Is CVE-2026-18218 a common vulnerability in Keycloak?

CVE-2026-18218 is a specific and critical vulnerability that users of Keycloak should be aware of and take action to mitigate.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203