CVE-2026-1486 Details
Description
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.
A vulnerability exists in Keycloak's JWT authorization grant flow. The server does not verify if an Identity Provider (IdP) is enabled before issuing tokens. This flaw allows an entity with access to a disabled IdP's signing key to generate valid JWT assertions, which Keycloak accepts, resulting in unauthorized access tokens. This issue affects Red Hat build of Keycloak 26.4.9.
Administrators should revoke or rotate the signing keys associated with any disabled Identity Provider in Keycloak to prevent unauthorized token issuance. Red Hat build of Keycloak 26.4.9 is available as a standalone server, as well as an integrated solution for OpenShift Container Platform.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 9, 2026CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:2365 | redhat-SADP | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/errata/RHSA-2026:2366 | redhat-SADP | AdvisoryBundleVendor |
| https://access.redhat.com/security/cve/CVE-2026-1486 | redhat-SADP | AdvisoryRemedyVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2433347 | redhat-SADP | Issue TrackingTechnical DescriptionVendor |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1486.json | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:2365 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/errata/RHSA-2026:2366 | [email protected] | AdvisoryBundleVendor |
| https://access.redhat.com/security/cve/CVE-2026-1486 | [email protected] | AdvisoryRemedyVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2433347 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-358 | Improperly Implemented Security Check for Standard | redhat-SADP |
| CWE-358 | Improperly Implemented Security Check for Standard | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat build of Keycloak | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | CVE Modified | [email protected] |
| Feb 9, 2026 | New CVE Received | [email protected] |
Volerion