CVE-2026-23552
Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue.
| CWE | CWE-346 |
| Vendor | apache software foundation |
| Product | apache camel |
| Published | Feb 23, 2026 |
| Last Updated | Feb 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache camel
Be the first to know when new critical vulnerabilities affecting apache software foundation apache camel are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache Camel
4.15.0 < 4.18.0
References
Credits
Andrea Cosentino Andrea Cosentino