CVE-2026-18572
Received Received - Intake

Time-Based Access Bypass in Keycloak

Vulnerability report for CVE-2026-18572, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: Red Hat, Inc.

Description

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
keycloak keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Keycloak's authorization service uses time policies to restrict resource access to specific hours. A flaw allows users to submit a fake time value in authorization requests, overriding the server's actual time. This bypasses time-based restrictions, letting unauthorized access to protected resources outside allowed hours.

Detection Guidance

To detect this vulnerability, monitor Keycloak authorization logs for requests containing unusual or fake time values. Check for requests where the time parameter does not match the server's actual time. Use log analysis tools to filter requests with time overrides.

Impact Analysis

If you rely on Keycloak for time-based access control, attackers could exploit this flaw to access sensitive resources during restricted hours. This may lead to data breaches, unauthorized actions, or compliance violations depending on the protected data.

Compliance Impact

This vulnerability could violate time-based access controls required by GDPR, HIPAA, or other regulations. Unauthorized access during restricted hours may result in data exposure, non-compliance penalties, or loss of audit trail integrity.

Mitigation Strategies

Update Keycloak to the latest patched version immediately to address the time override flaw in authorization requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18572. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart