CVE-2026-18218
MEDIUMKeycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero
Title source: cnaDescription
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
References (2)
Core 2
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-18218
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2508313
https://bugzilla.redhat.com/show_bug.cgi?id=2508313
Scores
CVSS v3
4.2
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-862
Status
published
Products (4)
Red Hat/Red Hat Build of Keycloak
Red Hat/Red Hat Data Grid 8
Red Hat/Red Hat JBoss Enterprise Application Platform Expansion Pack
Red Hat/Red Hat Single Sign-On 7
Published
Jul 31, 2026
Tracked Since
Jul 31, 2026