CVE-2026-18569
Received Received - Intake

Forced Logout via Unsigned Backchannel in Red Hat Keycloak

Vulnerability report for CVE-2026-18569, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Red Hat, Inc.

Description

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authentication and session management for applications. The issue occurs when an OIDC identity provider is configured to skip signature validation. In this specific setup, the system incorrectly accepts logout requests that have no cryptographic signature. An attacker who knows certain technical details about a user's session can use this flaw to force that user to be logged out, potentially disrupting their work.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the backchannel logout endpoint of Keycloak, an authentication system. When an OIDC identity provider skips signature validation, the system fails to verify logout requests properly. Attackers can exploit this by sending unsigned logout requests to forcibly log out users, disrupting their sessions.

Impact Analysis

If you use Keycloak with an OIDC identity provider that skips signature validation, an attacker could force you to log out of your session. This could disrupt your work, cause data loss, or lead to unauthorized access if sessions are not properly managed.

Mitigation Strategies

Ensure OIDC identity providers are configured to require cryptographic signature validation for logout requests. Review and update Keycloak settings to enforce signature checks on all logout endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18569. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart