THREAT OPS › Threat News › [NVD] CVE-2026-18218 (MEDIUM 4.2) — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm alread
[NVD] CVE-2026-18218 (MEDIUM 4.2) — A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm alread
CVE-2026-18218 CVSS: 4.2 MEDIUM Published: 2026-07-31T08:16:28.177
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place.
Indicators of compromise
- CVE-2026-18218cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18218