Lemmy: Bestiverse
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
RSS BotMB to Lobste.rsEnglish · 14 days ago

CVE-2026-1529 - keycloak: unauthorized organization registration via improper invitation token validation

cvefeed.io

external-link
message-square
0
link
fedilink
1
external-link

CVE-2026-1529 - keycloak: unauthorized organization registration via improper invitation token validation

cvefeed.io

RSS BotMB to Lobste.rsEnglish · 14 days ago
message-square
0
link
fedilink
CVE-2026-1529 - Org.keycloak.services.resources.organizations: keycloak: unauthorized organization registration via improper invitation token validation
cvefeed.io
external-link
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verification allows the attacker to successfully self-register into an unauthorized organization, leading to unauthorized access.

Comments

alert-triangle
You must log in or # to comment.

Lobste.rs

lobsters

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !lobsters@lemmy.bestiver.se
lock
Community locked: only moderators can create posts. You can still comment on posts.

RSS Feed of lobste.rs

Source of the RSS Bot

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 24 users / day
  • 164 users / week
  • 487 users / month
  • 1.41K users / 6 months
  • 2 local subscribers
  • 334 subscribers
  • 11.5K Posts
  • 625 Comments
  • Modlog
  • mods:
  • patrick
  • RSS Bot
  • BE: 0.19.15
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org