CVE-2026-18569
Keycloak-services: keycloak-services: oidc backchannel logout accepts unsigned forged logout tokens
Record summary
CVE-2026-18569 has a selected CVSS score of 3.7 (low).
Description
A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of KeycloakBrowse Red Hat / Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of KeycloakBrowse Red Hat / Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Default status: affected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform Expansion PackBrowse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesDefault status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |