{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1609.json"
      }
    ],
    "title": "org.keycloak/keycloak-quarkus-server: Keycloak: Unauthorized Access via JWT authorization grant with disabled users",
    "tracking": {
      "current_release_date": "2026-08-09T15:34:27+00:00",
      "generator": {
        "date": "2026-08-09T15:34:27+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.12"
        }
      },
      "id": "CVE-2026-1609",
      "initial_release_date": "2026-02-09T18:59:00+00:00",
      "revision_history": [
        {
          "date": "2026-02-09T18:59:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-09T15:20:13+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-09T15:34:27+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 8",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 8",
                  "product_id": "red_hat_jboss_enterprise_application_platform_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                  "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jbosseapxp"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "category": "product_version",
            "name": "keycloak-quarkus-server",
            "product": {
              "name": "keycloak-quarkus-server",
              "product_id": "keycloak-quarkus-server",
              "product_identification_helper": {
                "purl": "pkg:maven/org.keycloak/keycloak-quarkus-server"
              }
            }
          },
          {
            "category": "product_version",
            "name": "keycloak-quarkus-server-app",
            "product": {
              "name": "keycloak-quarkus-server-app",
              "product_id": "keycloak-quarkus-server-app",
              "product_identification_helper": {
                "purl": "pkg:maven/org.keycloak/keycloak-quarkus-server-app"
              }
            }
          },
          {
            "category": "product_version",
            "name": "keycloak-quarkus-server-deployment",
            "product": {
              "name": "keycloak-quarkus-server-deployment",
              "product_id": "keycloak-quarkus-server-deployment",
              "product_identification_helper": {
                "purl": "pkg:maven/org.keycloak/keycloak-quarkus-server-deployment"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "keycloak-quarkus-server as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server"
        },
        "product_reference": "keycloak-quarkus-server",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "keycloak-quarkus-server-app as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-app"
        },
        "product_reference": "keycloak-quarkus-server-app",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "keycloak-quarkus-server-deployment as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-deployment"
        },
        "product_reference": "keycloak-quarkus-server-deployment",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "keycloak-quarkus-server as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server"
        },
        "product_reference": "keycloak-quarkus-server",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "keycloak-quarkus-server-app as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-app"
        },
        "product_reference": "keycloak-quarkus-server-app",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "keycloak-quarkus-server-deployment as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-deployment"
        },
        "product_reference": "keycloak-quarkus-server-deployment",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Joy Gilbert",
            "Reynaldo Immanuel"
          ]
        }
      ],
      "cve": "CVE-2026-1609",
      "cwe": {
        "id": "CWE-284",
        "name": "Improper Access Control"
      },
      "discovery_date": "2026-01-29T12:08:43.064000+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server",
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-app",
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-deployment",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-app",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-deployment"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2435257"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "org.keycloak/keycloak-quarkus-server: Keycloak: Unauthorized Access via JWT authorization grant with disabled users",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "The Red Hat Product Security team has assessed this vulnerability as High severity; however, it only affects upstream Keycloak version 26.5.2, which includes a preview JWT authorization grant feature. No released Red Hat Build of Keycloak (RHBK) versions are impacted, as this feature has not been shipped in any downstream product. The issue arises from improper enforcement of user disabled-state checks during JWT authorization grant processing, potentially allowing unauthorized access when the preview feature is explicitly enabled. Red Hat products remain unaffected at this time.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server",
          "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-app",
          "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-deployment",
          "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server",
          "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-app",
          "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-deployment"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-1609"
        },
        {
          "category": "external",
          "summary": "RHBZ#2435257",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2435257"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-1609",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-1609"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-1609",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1609"
        },
        {
          "category": "external",
          "summary": "https://github.com/keycloak/keycloak/issues/46144",
          "url": "https://github.com/keycloak/keycloak/issues/46144"
        },
        {
          "category": "external",
          "summary": "https://github.com/keycloak/keycloak/releases/tag/26.5.3",
          "url": "https://github.com/keycloak/keycloak/releases/tag/26.5.3"
        }
      ],
      "release_date": "2026-02-09T18:59:00+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server",
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-app",
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-deployment",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-app",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-deployment"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server",
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-app",
            "red_hat_jboss_enterprise_application_platform_8:keycloak-quarkus-server-deployment",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-app",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:keycloak-quarkus-server-deployment"
          ]
        }
      ],
      "title": "org.keycloak/keycloak-quarkus-server: Keycloak: Unauthorized Access via JWT authorization grant with disabled users"
    }
  ]
}