CVE-2026-1529
HIGH 8.1EPSS 0.5%
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - EPSS
- 0.45% chance of exploitation in the next 30 days, 38th percentile
- Published
- 2026-02-09
- Updated
- 2026-07-15
Proof-of-concept exploits (3)
- 0x240x23elu/CVE-2026-15294★ · 2026-02-11
- ackemed/CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-toke…0★ · 2026-02-10
- ninjazan420/CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-…0★ · 2026-02-10