CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18218

mediumCVSS 4.2covered by 1 sourcefirst seen 2026-07-31
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

⚡ Watch CVE-2026-18218

Get an email if CVE-2026-18218 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-18218

CVE.org record

Embed the live status

CVE-2026-18218 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18218 status](https://www.csirts.com/badge/CVE-2026-18218)](https://www.csirts.com/cve/CVE-2026-18218)