Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users
Published Jul 16, 2026
8.1
HIGHCVSS 3.1
EPSS 0.56%
Description
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.
Affected products
-
- Version 26.5.0StatusaffectedConstraints<26.5.3
- Version
- 26.5.2
No data.
Red Hat JBoss Enterprise Application Platform 8
keycloak-quarkus-server
Not affected
Red Hat JBoss Enterprise Application Platform 8
keycloak-quarkus-server-app
Not affected
Red Hat JBoss Enterprise Application Platform 8
keycloak-quarkus-server-deployment
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
keycloak-quarkus-server
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
keycloak-quarkus-server-app
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
keycloak-quarkus-server-deployment
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-quarkus-server | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-quarkus-server-app | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-quarkus-server-deployment | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-quarkus-server | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-quarkus-server-app | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-quarkus-server-deployment | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, ensure that the `jwt-authorization-grant` preview feature is not enabled in Keycloak deployments. This feature is typically disabled by default. If it has been explicitly enabled, it should be disabled to prevent unauthorized access by disabled user accounts. Consult Keycloak documentation for specific instructions on managing preview features and configuration. A restart of the Keycloak service may be required after disabling the feature for the changes to take effect.
Red Hat statement
The Red Hat Product Security team has assessed this vulnerability as High severity; however, it only affects upstream Keycloak version 26.5.2, which includes a preview JWT authorization grant feature. No released Red Hat Build of Keycloak (RHBK) versions are impacted, as this feature has not been shipped in any downstream product. The issue arises from improper enforcement of user disabled-state checks during JWT authorization grant processing, potentially allowing unauthorized access when the preview feature is explicitly enabled. Red Hat products remain unaffected at this time.
Red Hat mitigation
To mitigate this issue, ensure that the `jwt-authorization-grant` preview feature is not enabled in Keycloak deployments. This feature is typically disabled by default. If it has been explicitly enabled, it should be disabled to prevent unauthorized access by disabled user accounts. Consult Keycloak documentation for specific instructions on managing preview features and configuration. A restart of the Keycloak service may be required after disabling the feature for the changes to take effect.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-1609 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2435257 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44841 Advisory
- https://github.com/keycloak/keycloak/issues/46144 Issue Tracking
- https://github.com/keycloak/keycloak/releases/tag/26.5.3 Release Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-1609
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1609.json Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-1609
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-1609 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2435257 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-44841 | Advisory | |
| https://github.com/keycloak/keycloak/issues/46144 | Issue Tracking | |
| https://github.com/keycloak/keycloak/releases/tag/26.5.3 | Release Notes | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-1609 | ||
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1609.json | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2026-1609 |
Change history (0)
No recorded changes yet.