CVE-2026-23552

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*

History

26 Feb 2026, 16:46

Type Values Removed Values Added
CPE cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*
References () https://camel.apache.org/security/CVE-2026-23552.html - () https://camel.apache.org/security/CVE-2026-23552.html - Vendor Advisory
References () https://github.com/oscerd/CVE-2026-23552 - () https://github.com/oscerd/CVE-2026-23552 - Exploit, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2026/02/18/7 - () http://www.openwall.com/lists/oss-security/2026/02/18/7 - Mailing List, Third Party Advisory
First Time Apache
Apache camel
Summary
  • (es) Elusión de la aceptación de tokens entre dominios (realms) en el componente KeycloakSecurityPolicy de Apache Camel Keycloak. La política de seguridad KeycloakSecurityPolicy de Camel-Keycloak no valida la declaración 'iss' (emisor) de los tokens JWT contra el dominio (realm) configurado. Un token emitido por un dominio (realm) de Keycloak es aceptado silenciosamente por una política configurada para un dominio (realm) completamente diferente, rompiendo el aislamiento de inquilinos. Este problema afecta a Apache Camel: desde la versión 4.15.0 hasta antes de la 4.18.0. Se recomienda a los usuarios actualizar a la versión 4.18.0, que corrige el problema.

23 Feb 2026, 16:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

23 Feb 2026, 10:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/02/18/7 -

23 Feb 2026, 09:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 09:17

Updated : 2026-02-26 16:46


NVD link : CVE-2026-23552

Mitre link : CVE-2026-23552

CVE.ORG link : CVE-2026-23552


JSON object : View

Products Affected

apache

  • camel
CWE
CWE-346

Origin Validation Error