🔐 CVE Alert

CVE-2026-23552

CRITICAL 9.1

Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue.

CWE CWE-346
Vendor apache software foundation
Product apache camel
Published Feb 23, 2026
Last Updated Feb 23, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache camel

Be the first to know when new critical vulnerabilities affecting apache software foundation apache camel are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Camel
4.15.0 < 4.18.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
camel.apache.org: https://camel.apache.org/security/CVE-2026-23552.html github.com: https://github.com/oscerd/CVE-2026-23552 openwall.com: http://www.openwall.com/lists/oss-security/2026/02/18/7

Credits

Andrea Cosentino Andrea Cosentino