{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-30T10:07:47Z",
  "bugzilla" : {
    "description" : "keycloak-services: keycloak-services: UMA claim token can override authorization time-policy evaluation attributes",
    "id" : "2509763",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2509763"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-863",
  "details" : [ "Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.", "Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times." ],
  "statement" : "The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to be an authenticated user and the target resource must be specifically protected by a time-based authorization policy. Successful exploitation allows an attacker to bypass temporal access controls and obtain permissions outside of allowed time windows. The vulnerability's root cause is the improper merging of user-supplied claims which allows them to overwrite trusted server-side evaluation attributes.",
  "acknowledgement" : "Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.",
  "package_state" : [ {
    "product_name" : "Red Hat Build of Keycloak",
    "fix_state" : "Affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:build_keycloak:"
  }, {
    "product_name" : "Red Hat Build of Keycloak",
    "fix_state" : "Affected",
    "package_name" : "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9",
    "cpe" : "cpe:/a:redhat:build_keycloak:"
  }, {
    "product_name" : "Red Hat Build of Keycloak",
    "fix_state" : "Affected",
    "package_name" : "rhbk-openshift-rhel9/rhbk-openshift-rhel9",
    "cpe" : "cpe:/a:redhat:build_keycloak:"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-18572\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-18572" ],
  "name" : "CVE-2026-18572",
  "csaw" : false
}