Vulnerability Description
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | - |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-18218Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2508313Issue TrackingVendor Advisory
FAQ
What is CVE-2026-18218?
CVE-2026-18218 is a vulnerability with a CVSS score of 4.2 (MEDIUM). A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" pol...
How severe is CVE-2026-18218?
CVE-2026-18218 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18218?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Build Of Keycloak.