CVE-2026-23552P3CRITICALCVSS 9.1≥ 4.15.0, < 4.18.3·≥ 4.19.0, < 4.21.02026-02-23
CVE-2026-23552 [CRITICAL] CWE-346 CVE-2026-23552: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.
The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tena
nvd