THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18218 (MEDIUM 4.2) — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm alread

[NVD] CVE-2026-18218 (MEDIUM 4.2) — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm alread

lownvdPublished 2026-07-31

CVE-2026-18218 CVSS: 4.2 MEDIUM Published: 2026-07-31T08:16:28.177

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18218