CVE-2026-23552 describes a critical Cross-Realm Token Acceptance Bypass in the Apache Camel Keycloak component, affecting versions from 4.15.0 before 4.18.0. This vulnerability allows a KeycloakSecurityPolicy configured for one realm to accept JWT tokens issued by a different realm, thereby breaking tenant isolation. With a CVSS score of 9.1 (CRITICAL), this issue presents a high-impact attack vector (AV:N) with low attack complexity (AC:L), potentially leading to high confidentiality and integrity impacts (C:H/I:H) without user interaction (UI:N). Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.15.0, < 4.18.0CPE match | cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Camel: KeycloakSecurityPolicy does not validate issuer of JWT tokens against configured realm
Feb 23, 2026https://camel.apache.org/security/CVE-2026-23552.html: CVE-2026-23552: Apache Camel: Camel-Keycloak: Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy
Feb 18, 2026