CVE-2026-23552

CRITICAL

Apache Camel 4.15.0-4.17.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue.

Scores

CVSS v3 9.1
EPSS 0.0004
EPSS Percentile 12.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (2)
apache/camel 4.15.0 - 4.18.0
org.apache.camel/camel-keycloak 4.15.0 - 4.18.0Maven
Published Feb 23, 2026
Tracked Since Feb 23, 2026