CVE-2026-1609 Details
Description
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.
A vulnerability exists in Keycloak's JWT authorization grant preview feature, specifically in version 26.5.2. When this feature is enabled, Keycloak does not properly validate the disabled status of user accounts during JWT authorization processing. This flaw allows remote attackers with low privileges to exploit the system by using a valid assertion token from an external identity provider to obtain a JWT for a disabled user, thereby gaining unauthorized access to sensitive resources.
To address this vulnerability, disable the 'jwt-authorization-grant' preview feature in Keycloak deployments. This feature is usually disabled by default, but if it has been turned on, it should be disabled to prevent unauthorized access through disabled user accounts. After disabling the feature, a restart of the Keycloak service may be necessary for the changes to take effect.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-1609 | redhat-SADP | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2435257 | redhat-SADP | Issue TrackingVendor Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1609.json | redhat-SADP | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-1609 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2435257 | [email protected] | Issue TrackingVendor Advisory |
| https://github.com/keycloak/keycloak/issues/46144 | [email protected] | Issue Tracking |
| https://github.com/keycloak/keycloak/releases/tag/26.5.3 | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | redhat-SADP |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | 26.5.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 9, 2026 | Initial Analysis | [email protected] |
| Jul 16, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | CVE Modified | redhat-SADP |
| Jul 16, 2026 | New CVE Received | [email protected] |