Description
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
Published: 2026-08-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Keycloak services provide time‑based access restrictions, allowing administrators to limit resource access to specific hours. The vulnerability allows a user to supply a fabricated time value in an authorization request that overrides the server’s actual timestamp, effectively bypassing the time restrictions and granting access to protected resources at unauthorized times. This flaw manifests as an authorization bypass (CWE‑863).

Affected Systems

Affected products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. All versions prior to the published fix are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the extremely low EPSS score (< 1%) suggests that exploitation is unlikely, and it is not currently listed in the CISA KEV catalog. The likely attack vector requires the attacker to control or forge UMA claim tokens in an authorization request; such a token can override the server time, allowing the attacker to access resources during blocked windows. The risk is moderate in environments that rely heavily on time‑based restriction enforcement.

Generated by OpenCVE AI on August 3, 2026 at 09:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Red Hat updates for Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7 that contain the fix for the claim‑token time‑policy override.
  • Revoke any tokens that contain manipulated or forged UMA claim values and generate new tokens that enforce the correct server timestamp.
  • Configure logging of all token claim values and audit logs for anomalies related to time claims, enabling quicker detection of unauthorized overrides.
  • Disable unnecessary claim overrides or restrict the UMA claim to a trusted set of fields to reduce the surface area for exploitation.

Generated by OpenCVE AI on August 3, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on

Sun, 02 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 02 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.
Title Keycloak-services: keycloak-services: uma claim token can override authorization time-policy evaluation attributes
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
Weaknesses CWE-863
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-03T15:51:23.871Z

Reserved: 2026-08-02T05:15:43.624Z

Link: CVE-2026-18572

cve-icon Vulnrichment

Updated: 2026-08-03T15:51:11.876Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-02T06:16:42.290

Modified: 2026-08-07T18:24:33.917

Link: CVE-2026-18572

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T10:07:47Z

Links: CVE-2026-18572 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T09:30:17Z

Weaknesses