Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Keycloak
Redhat data Grid Redhat jboss Enterprise Application Platform Expansion Pack Redhat single Sign On |
|
| Vendors & Products |
Redhat build Of Keycloak
Redhat data Grid Redhat jboss Enterprise Application Platform Expansion Pack Redhat single Sign On |
Sat, 01 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspection responses, attempts to introspect a token issued for a different audience. Although the endpoint correctly identifies the token as inactive for that client, it still returns the full set of token claims within a signed JWT field. This allows an unauthorized client to bypass audience-based restrictions and access sensitive information contained in the token. | |
| Title | Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat jboss Data Grid Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:jboss_data_grid:8 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat jboss Data Grid Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-31T19:32:57.561Z
Reserved: 2026-07-29T08:13:24.248Z
Link: CVE-2026-18208
Updated: 2026-07-31T19:32:53.507Z
Status : Analyzed
Published: 2026-07-31T08:16:27.323
Modified: 2026-08-07T14:47:32.323
Link: CVE-2026-18208
OpenCVE Enrichment
Updated: 2026-08-02T20:33:14Z