LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-23552

CVE-2026-23552 - Vulnerability Analysis

CriticalCVSS: 9.1

Last Updated: February 23, 2026

Apache Camel Keycloak - Broken Access Control

Published: February 23, 2026Updated: February 23, 2026PoC AvailableRemote Exploitable

Overview

Apache Camel Keycloak component 4.15.0 to <4.18.0 contains a broken access control caused by lack of issuer claim validation in KeycloakSecurityPolicy, letting attackers bypass tenant isolation by using tokens from other realms, exploit requires crafted JWT tokens.

Severity & Score

Severity: Critical
CVSS Score: 9.1
EPSS Score: 1.5%(Probability of exploitation in next 30 days)

Impact

Attackers can bypass tenant isolation, potentially accessing or manipulating data across different realms.

Mitigation

Upgrade to version 4.18.0.

Social Media Activity(2 posts)

Offensive Sequence
Offensive Sequence
@offseq
Feb 24, 2026

🚨 CRITICAL: CVE-2026-23552 in Apache Camel 4.15.0 – 4.17.x breaks tenant isolation — JWT tokens from any Keycloak realm may be accepted! Upgrade to 4.18.0 ASAP to secure multi-tenant systems. https://radar.offseq.com/threat/cve-2026-23552-cwe-346-origin-validation-error-in--099c72c7 #OffSeq #ApacheCamel #Vuln #Keycloak

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Feb 23, 2026

šŸ”“ CVE-2026-23552 - Critical (9.1) Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-23552/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

GitHub Repositories(1 repo)

Details

CVE ID
CVE-2026-23552
Severity
Critical
CVSS Score
9.1
Type
broken_access_control
Status
unconfirmed
EPSS
1.5%
Social Posts
2

CWE

  • CWE-346

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Score

1.5%Probability of exploitation in the next 30 days