cbcvebase.
CVE-2026-23552
published 2026-02-23

CVE-2026-23552: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak KeycloakSecurityPolicy does not validate the…

PriorityP357critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.40%
32.4th percentile
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apachecamel
apachecamel>= 4.15.0 < 4.18.04.18.0
apachecamel>= 4.15.0 < 4.18.34.18.3
apachecamel>= 4.19.0 < 4.21.04.21.0
apache_software_foundationapache_camel_keycloak>= 4.15.0 < 4.18.34.18.3
apache_software_foundationapache_camel_keycloak>= 4.19.0 < 4.21.04.21.0

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_apache9.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.