VYPR

keycloak-quarkus-server

by Keycloak

CVEs (1)

  • CVE-2026-1609Jul 16, 2026
    risk 0.00cvss epss 0.01

    A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can…