{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1486.json"
      }
    ],
    "title": "org.keycloak.protocol.oidc.grants: Disabled identity providers are still accepted for JWT Authorization Grant",
    "tracking": {
      "current_release_date": "2026-06-30T04:12:04+00:00",
      "generator": {
        "date": "2026-06-30T04:12:04+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-1486",
      "initial_release_date": "2026-02-09T18:23:00+00:00",
      "revision_history": [
        {
          "date": "2026-02-09T18:23:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-03-16T08:31:25+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T04:12:04+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Keycloak 26.4.9",
                "product": {
                  "name": "Red Hat build of Keycloak 26.4.9",
                  "product_id": "Red Hat build of Keycloak 26.4.9",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:build_keycloak:26.4::el9"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat build of Keycloak 26.4",
                "product": {
                  "name": "Red Hat build of Keycloak 26.4",
                  "product_id": "9Base-RHBK-26.4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:build_keycloak:26.4::el9"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat build of Keycloak"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
                "product": {
                  "name": "rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
                  "product_id": "rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b?arch=s390x&repository_url=registry.redhat.io/rhbk/keycloak-rhel9&tag=26.4-11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
                "product": {
                  "name": "rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
                  "product_id": "rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1?arch=s390x&repository_url=registry.redhat.io/rhbk/keycloak-rhel9-operator&tag=26.4-10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "s390x"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
                "product": {
                  "name": "rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
                  "product_id": "rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112?arch=amd64&repository_url=registry.redhat.io/rhbk/keycloak-rhel9&tag=26.4-11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
                "product": {
                  "name": "rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
                  "product_id": "rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b?arch=amd64&repository_url=registry.redhat.io/rhbk/keycloak-operator-bundle&tag=26.4.9-1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
                "product": {
                  "name": "rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
                  "product_id": "rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4?arch=amd64&repository_url=registry.redhat.io/rhbk/keycloak-rhel9-operator&tag=26.4-10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
                "product": {
                  "name": "rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
                  "product_id": "rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365?arch=arm64&repository_url=registry.redhat.io/rhbk/keycloak-rhel9&tag=26.4-11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
                "product": {
                  "name": "rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
                  "product_id": "rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b?arch=arm64&repository_url=registry.redhat.io/rhbk/keycloak-rhel9-operator&tag=26.4-10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
                "product": {
                  "name": "rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
                  "product_id": "rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd?arch=ppc64le&repository_url=registry.redhat.io/rhbk/keycloak-rhel9&tag=26.4-11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
                "product": {
                  "name": "rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
                  "product_id": "rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:oci/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0?arch=ppc64le&repository_url=registry.redhat.io/rhbk/keycloak-rhel9-operator&tag=26.4-10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "ppc64le"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64 as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64"
        },
        "product_reference": "rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x"
        },
        "product_reference": "rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64 as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64"
        },
        "product_reference": "rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64 as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64"
        },
        "product_reference": "rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le"
        },
        "product_reference": "rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x"
        },
        "product_reference": "rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64 as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64"
        },
        "product_reference": "rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le"
        },
        "product_reference": "rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64 as a component of Red Hat build of Keycloak 26.4",
          "product_id": "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64"
        },
        "product_reference": "rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
        "relates_to_product_reference": "9Base-RHBK-26.4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Reynaldo Immanuel",
            "Joy Gilbert Dan"
          ]
        }
      ],
      "cve": "CVE-2026-1486",
      "cwe": {
        "id": "CWE-358",
        "name": "Improperly Implemented Security Check for Standard"
      },
      "discovery_date": "2026-01-27T13:34:53.016000+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2433347"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFromIssuer) retrieves the IdP configuration but does not filter for isEnabled=false. If an administrator disables an IdP (e.g., due to a compromise or offboarding), an entity possessing that IdP's signing key can still generate valid JWT assertions that Keycloak accepts, resulting in the issuance of valid access tokens.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "org.keycloak.protocol.oidc.grants: Disabled identity providers are still accepted for JWT Authorization Grant",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability is rated Important for Red Hat products because Keycloak, when configured with JWT authorization grants, fails to verify the enabled status of an Identity Provider (IdP). An attacker possessing the IdP's signing key can issue valid access tokens even if the IdP has been administratively disabled, leading to unauthorized access.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "9Base-RHBK-26.4:rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
          "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
          "Red Hat build of Keycloak 26.4.9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-1486"
        },
        {
          "category": "external",
          "summary": "RHBZ#2433347",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433347"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-1486",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1486"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-1486",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1486"
        }
      ],
      "release_date": "2026-02-09T18:23:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-02-09T20:41:06+00:00",
          "details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.",
          "product_ids": [
            "9Base-RHBK-26.4:rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:2366"
        },
        {
          "category": "vendor_fix",
          "date": "2026-02-09T20:37:33+00:00",
          "details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.",
          "product_ids": [
            "Red Hat build of Keycloak 26.4.9"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:2365"
        },
        {
          "category": "workaround",
          "details": "To mitigate this issue, administrators should immediately revoke or rotate the signing keys associated with any Identity Provider that has been disabled in Keycloak. This operational control is crucial to prevent unauthorized token issuance by ensuring that compromised or offboarded IdP keys cannot be used to generate valid JWT assertions.",
          "product_ids": [
            "9Base-RHBK-26.4:rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
            "Red Hat build of Keycloak 26.4.9"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "9Base-RHBK-26.4:rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
            "Red Hat build of Keycloak 26.4.9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "9Base-RHBK-26.4:rhbk/keycloak-operator-bundle@sha256:fd235c7a4820865af18c35441296ae7d40bbd2eea2f7c7b16d5ce9f658c5653b_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:3fb03c48b66c39429e64eb4f20a110fea755e102285778aae0a8229cb5681be1_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:718d63c9de563c7339fc6800d7f014c186467b11b2c9b058f88fa9883283180b_arm64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:aa64ecc958ea5569ba023b51d7df1bbc347f7df459a92a23e8b058ae4622b6d4_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9-operator@sha256:bcc01dface0582789dae5eb2919ac8ba5a4f5e3e36909a7983a32a0a05d14ae0_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:3f38533ab14d09b0d86394d73a61f3304eef2a19a65e5d5cf87107794d4fc23b_s390x",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:71fbf006f8e158fe29b47dfce09757bb004715395c5063b8e317ffd5ef437112_amd64",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:7d3668580a61da509f7b473f8df9197548fb71c465eeaaa53802e7d4e99b84fd_ppc64le",
            "9Base-RHBK-26.4:rhbk/keycloak-rhel9@sha256:8df9fbf1320938c3e708241c78796bcc832d1a11b85be78dd37bbc54630e6365_arm64",
            "Red Hat build of Keycloak 26.4.9"
          ]
        }
      ],
      "title": "org.keycloak.protocol.oidc.grants: Disabled identity providers are still accepted for JWT Authorization Grant"
    }
  ]
}