THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18572 (MEDIUM 6.5) — Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request tha

[NVD] CVE-2026-18572 (MEDIUM 6.5) — Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request tha

mednvdPublished 2026-08-02

CVE-2026-18572 CVSS: 6.5 MEDIUM Published: 2026-08-02T06:16:42.290

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18572