CVE-2026-1529
Org.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validation
- Published
- Feb 9, 2026
- Updated
- Jul 15, 2026
- Assigning CNA
- redhat
- Evidence observed
- Aug 25, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NLow · next 30 days
- Percentile
- 39.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.
Sources
4- CVE-2026-1529Exploit
Keycloak: Unauthorized organization registration via improper invitation token validation
Exploit tool for CVE-2026-1529, demonstrating unauthorized organization registration in Keycloak via JWT token manipulation. Includes token generation, manipulation, and user registration with report generation.
- CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validationExploit
CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token validation. This exploit tool demonstrates the vulnerability by manipulating JWT tokens to register users in unauthorized organizations.
Keycloak: Unauthorized organization registration via improper invitation token validation
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.