What is CVE-2026-18569?
CVE-2026-18569 is a vulnerability in the Keycloak-services backchannel logout endpoint, affecting authentication and session management. The flaw occurs when an OIDC identity provider is configured to skip signature validation, potentially enabling session hijacking. Users of Red Hat Build of Keycloak should apply security updates.
Azərbaycanca: CVE-2026-18569 Keycloak xidmətlərinin backchannel logout endpoint-də autentifikasiya və sessiya idarəetməsində boşluqdur. OIDC identity provider imza doğrulamasını (signature validation) keçdikdə zəiflik yaranır, bu da sessiya qaçırma riski yarada bilər. Keycloak istifadəçiləri təhlükəsizlik yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Red Hat
FAQ2
What component in Keycloak is affected by the CVE-2026-18569 vulnerability?
This vulnerability affects the authentication and session management in the Keycloak-services backchannel logout endpoint.
Under what condition can this flaw be exploited?
The flaw occurs when an OIDC identity provider is configured to skip signature validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.