Vulnerability record · CVE-2026-1609 · published 16 July 2026
CVE-2026-1609: Redhat build of keycloak improper access control vulnerability
Redhat · Build Of Keycloak
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.
Description
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-1609 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2435257 | Issue TrackingVendor Advisory |
| https://github.com/keycloak/keycloak/issues/46144 | Issue Tracking |
| https://github.com/keycloak/keycloak/releases/tag/26.5.3 | Release Notes |
| https://access.redhat.com/security/cve/CVE-2026-1609 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2435257 | Issue TrackingVendor Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1609.json | Vendor Advisory |
Track CVE-2026-1609 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-1609), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.