CVE-2026-1529 is a Keycloak vulnerability in the organization invitation/self-registration flow where invitation tokens (JWTs) are parsed without cryptographic signature verification. An attacker can take a legitimate invitation token and tamper with JWT payload fields—specifically the organization ID and the target email—without invalidating the token, then use the modified token to self-register into an organization they were not invited to, resulting in unauthorized organization access. The issue is described as affecting Keycloak versions prior to 26.1.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository purpose: a Python-based exploit tool targeting Keycloak CVE-2026-1529 ("Unauthorized organization registration via improper invitation token validation"). It performs network-based checks to confirm a Keycloak instance is reachable, probes for version indicators, tests the organizations endpoint, then generates or manipulates an invitation JWT and uses it to automate unauthorized registration and verify login. Successful runs print created credentials and save a report under output/reports/. Main capabilities (from code/docs): - Target validation and fingerprinting: HTTPClient.check_keycloak_health() probes /health, /realms/master, /, /auth/realms/master; detect_keycloak_version() probes /version, /realms/master, and /auth/realms/master/.well-known/openid-configuration and checks X-Keycloak-Version. - Vulnerability assessment: KeycloakExploit.check_target_vulnerability() confirms reachability and that /organizations is accessible (treating 200/401/403/404 as "accessible"). - Token operations: utils/jwt_utils.py can generate an "invitation" JWT (claims: org_id, email, iat, exp, type) and can decode/manipulate an existing token to change org_id/email and re-sign using HS256 with a configured secret. - Exploitation workflow (partially truncated in provided content but described in README/QUICKSTART/SETUP): uses the invitation token to drive unauthorized organization/user registration, then attempts login verification; outputs a login link and writes a timestamped report. Repository structure: - keycloak-exploit.py: entry point CLI; loads config, sets up HTTP client and JWT manipulator, runs vulnerability check and exploit flow, prints results. - config/default_config.json: defaults for usernames/passwords/emails, HTTP timeouts/retries, JWT algorithm/secret, and target endpoint paths (/realms, /organizations, /register, /login). - utils/http_utils.py: requests-based HTTP client with urllib3 Retry (allowed_methods) and helper probes for health/version/endpoint accessibility. - utils/jwt_utils.py: JWT generation/decoding/manipulation (PyJWT). - utils/crypto_utils.py: URL validation and random username/password/string generation. - Documentation: README.md, QUICKSTART.md, COMPLETE_SETUP_GUIDE.md explain setup, usage flags (-t token, -o org-id, -c config, -d debug), and expected output. Notable fingerprintable observables: - Network paths used for probing/fingerprinting: /health, /version, /realms/master, /auth/realms/master, /auth/realms/master/.well-known/openid-configuration. - Configured target endpoints: /organizations, /register, /login, /realms. - Local output locations: logs/, output/reports/. Assessment: - Not part of a larger exploit framework (standalone script). - Appears to be an operational exploit (not just detection) because it includes JWT forging/manipulation logic and an automated registration/login workflow, plus report generation.
Repository is a Python-based exploit tool targeting CVE-2026-1529 in Keycloak, described as “Unauthorized organization registration via improper invitation token validation.” The core idea is JWT invitation token abuse: the tool decodes a JWT without verifying the signature, modifies fields such as org_id and email, then re-encodes/signs a token (HS256 with a configured secret) and uses it to register a new user in an organization the attacker should not be able to join. Structure and key components: - keycloak-exploit.py: Main CLI entry point. Loads config (config/default_config.json), initializes an HTTP client and JWT manipulator, performs a vulnerability check (Keycloak health + version detection + /organizations endpoint test), then runs the exploit flow (token generation/manipulation, user registration, login verification) and prints results. Creates local directories logs/, output/, output/reports/. - config/default_config.json: Default settings including credentials to create (admin_user_2026 / KeycloakCVE2026!), JWT algorithm/secret, timeouts/retries, and endpoint paths (/realms, /organizations, /register, /login) plus default HTTP headers. - utils/http_utils.py: Requests-based HTTP wrapper with retries. Implements GET/POST/etc and helper checks: /health for reachability, /admin/serverinfo for version detection, and generic endpoint testing. - utils/jwt_utils.py: JWT manipulation utilities. Notably decodes JWT by base64-decoding header/payload without signature verification, then manipulates org_id/email and invitation fields, and re-encodes using PyJWT. - utils/crypto_utils.py: Helper functions for generating usernames/passwords/emails and validating URL/email formats. - templates/: Contains an exploit template (templates/exploit_template.py) showing how to extend/customize exploitation (batch exploitation, advanced token modifications) and a detailed report template (templates/report_template.txt). Exploit capabilities (as implemented/described): - Network-based targeting of a Keycloak base URL. - Fingerprinting/validation: health check and optional version detection. - Endpoint probing: tests organization endpoint availability. - JWT invitation token generation and/or manipulation (org_id/email changes; invitation metadata updates). - Unauthorized user registration via POST to the configured registration endpoint using the manipulated token. - Post-exploitation validation by attempting login and producing a login link. - Reporting/logging: writes reports under output/reports and references logs/exploit.log for troubleshooting. Overall, this is an operational PoC-style exploit tool (not a framework module) with configurable endpoints and JWT settings, intended to demonstrate unauthorized account creation/organization enrollment in vulnerable Keycloak deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JWT signature verification bypass affecting Keycloak invitation tokens, allowing forged invitation JWTs to be accepted without cryptographic signature verification, enabling cross-organization self-registration.
A Keycloak invitation-token/JWT handling flaw where insufficient cryptographic signature verification allows tampering with JWT payload fields (organization ID and target email) to self-register into unauthorized organizations, resulting in unauthorized access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.