THREAT OPS › Threat News › [NVD] CVE-2026-18572 (MEDIUM 6.5) — Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request tha
[NVD] CVE-2026-18572 (MEDIUM 6.5) — Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request tha
CVE-2026-18572 CVSS: 6.5 MEDIUM Published: 2026-08-02T06:16:42.290
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the
Indicators of compromise
- CVE-2026-18572cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18572