{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-13T15:21:42.581","vulnerabilities":[{"cve":{"id":"CVE-2026-23552","sourceIdentifier":"security@apache.org","published":"2026-02-23T09:17:00.857","lastModified":"2026-02-26T16:46:16.643","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component. \n\nThe Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation.\nThis issue affects Apache Camel: from 4.15.0 before 4.18.0.\n\nUsers are recommended to upgrade to version 4.18.0, which fixes the issue."},{"lang":"es","value":"Omisión de la aceptación de tokens entre dominios (realms) en el componente KeycloakSecurityPolicy de Apache Camel Keycloak.\n\nLa política de seguridad KeycloakSecurityPolicy de Camel-Keycloak no valida la declaración 'iss' (emisor) de los tokens JWT contra el dominio (realm) configurado. Un token emitido por un dominio (realm) de Keycloak es aceptado silenciosamente por una política configurada para un dominio (realm) completamente diferente, rompiendo el aislamiento de inquilinos.\nEste problema afecta a Apache Camel: desde la versión 4.15.0 hasta antes de la 4.18.0.\n\nSe recomienda a los usuarios actualizar a la versión 4.18.0, que corrige el problema."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15.0","versionEndExcluding":"4.18.0","matchCriteriaId":"E575766B-E717-45A6-BD34-2C004B8EA67F"}]}]}],"references":[{"url":"https://camel.apache.org/security/CVE-2026-23552.html","source":"security@apache.org","tags":["Vendor Advisory"]},{"url":"https://github.com/oscerd/CVE-2026-23552","source":"security@apache.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2026/02/18/7","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]}]}}]}