Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 40.5%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-1609


Contact Us

Shodan ® - All rights reserved