HomeCVE Intelligence › CVE-2026-1609
CVSS 8.1 HIGH 🔴 ACTIVELY EXPLOITED Security Vulnerability

CVE-2026-1609: A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview f…

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the users disabled status during JWT authorization gr…

8.1CVSS Score
HIGHSeverity
NOCISA KEV
0.5%EPSS Score
Security VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-1609
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeSecurity Vulnerability
CVSS Score8.1 (HIGH)
EPSS Score0.5% probability of exploitation in the next 30 days
Actively Exploited✅ Yes
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the users disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-1609","confidence_score":23.5,"first_seen":"2026-07-18","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-1609 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence