What is CVE-2026-18572?
A flaw was discovered in Keycloak's time-based access policies, where an attacker can include a fake time value in the authorization request to bypass restrictions and access resources outside of allowed business hours. Administrators should update Keycloak to the latest patched version to mitigate this issue.
Azərbaycanca: Keycloak-in zaman əsaslı giriş siyasətində boşluq aşkarlanıb. Təcavüzkar icazə sorğusunda saxta vaxt dəyəri göndərərək məhdudlaşdırılmış resurslara biznes saatları xaricində daxil ola bilər. Bu problemi aradan qaldırmaq üçün Keycloak-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What is CVE-2026-18572?
It is a flaw discovered in Keycloak's time-based access policies, where an attacker can include a fake time value in the authorization request to bypass restrictions and access resources outside of allowed business hours.
How to protect against CVE-2026-18572?
Administrators should update Keycloak to the latest patched version to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.