
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1529 is a JWT signature verification bypass vulnerability in Keycloak that allows an authenticated attacker to modify organization invitation tokens and self-register into unauthorized organizations. The flaw exists in the org.keycloak.services.resources.organizations component and was disclosed on February 9, 2026. Affected versions include org.keycloak:keycloak-services < 26.2.13, >= 26.3.0 and < 26.4.9, and >= 26.5.0 and < 26.5.3. It carries a CVSS v3.1 base score of 8.1 (High) (Red Hat Advisory, Github Advisory).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). During the organization registration flow, Keycloak parses invitation tokens (JWTs) without verifying their cryptographic signatures, meaning an attacker can decode a legitimate invitation JWT, tamper with the org_id (organization ID) and eml (target email) fields in the payload, and re-submit the modified token to register into an arbitrary organization. The attack requires network access and low privileges (possession of any valid invitation token), but no user interaction, and has low attack complexity (Red Hat Bugzilla, Github Advisory). A public proof-of-concept exploit is available on GitHub (PoC).
Successful exploitation allows an attacker to gain unauthorized membership in any Keycloak-managed organization, resulting in high confidentiality and integrity impact with no availability impact. An attacker who joins an unauthorized organization can access sensitive organizational resources, data, and potentially perform actions within that organization's scope. This could facilitate lateral movement within multi-tenant environments where Keycloak manages access control across multiple organizations (Github Advisory, Red Hat Advisory).
jwt.io, python-jwt, or base64 CLI) to decode the token's payload without verifying the signature. Identify the org_id (organization ID) and eml (target email) fields.org_id value to the ID of the target unauthorized organization, and optionally update the eml field to the attacker's email address.org_id or eml values; repeated registration attempts using the same or similar invitation tokens from different source IPs.ORGANIZATION_MEMBER entries created around the time of suspicious registration events (Red Hat Bugzilla).Red Hat has released patched versions addressing this vulnerability: 26.2.13, 26.4.9, and 26.5.3 of org.keycloak:keycloak-services. Corresponding Red Hat build of Keycloak advisories (RHSA-2026:2363, RHSA-2026:2364, RHSA-2026:2365, RHSA-2026:2366) are available for standalone and OpenShift container deployments. Organizations should upgrade to a patched version immediately, audit existing organization memberships for unauthorized entries, and consider implementing administrator approval workflows for organization invitations as an additional control (Red Hat RHSA-2026:2363, Red Hat RHSA-2026:2365, Github Advisory).
The vulnerability received coverage from security news outlets including The Hacker Wire (via Mastodon and Bluesky) and was included in Cyble's weekly vulnerability report for the week of February 19, 2026. The Secret CISO newsletter also referenced the vulnerability. Community discussion appeared on Lobste.rs, and the vulnerability was tracked by multiple aggregators including VulnDB and CVEFeed. Emerging Threats added detection rules in their March 5, 2026 ruleset update, and a Nuclei template pull request was submitted in March 2026, reflecting active community interest in detection (Cyble Report, Emerging Threats).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."