CVE-2026-46455 is an insufficient session-expiration vulnerability in the Apache Camel Keycloak component. KeycloakSecurityHelper.parseAndVerifyAccessToken constructs a Keycloak TokenVerifier using checks for subject existence and the realm URL issuer, but omits TokenVerifier.IS_ACTIVE. Because default checks are not installed unless withDefaultChecks() is used, the helper does not validate the access token's exp expiration or nbf not-before claims. It verifies the token signature, subject, and issuer while accepting expired or not-yet-valid tokens. The issue affects Apache Camel camel-keycloak versions 4.18.0 through before 4.18.3 and 4.19.0 through before 4.21.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact Java/Spring Boot proof-of-concept reproducer for CVE-2026-46455, an authentication weakness in Apache Camel's camel-keycloak component. The project contains 8 files total, with the main logic in src/main/java/com/example/ExploitController.java and the Spring Boot bootstrap in Application.java. Build/runtime scaffolding is provided by pom.xml, Dockerfile, docker-compose.yml, and application.properties. The exploit capability is not remote code execution; it is an authentication-bypass demonstration. The controller exposes a GET endpoint at /exploit/attack. When called, it generates an RSA key pair in memory, constructs a Keycloak AccessToken object, sets a valid issuer and subject, deliberately sets iat/exp so the token is already expired, signs the token as a JWT, and then passes it to KeycloakSecurityHelper.parseAndVerifyAccessToken. On vulnerable camel-keycloak versions, that helper verifies signature, subject, and issuer but omits TokenVerifier.IS_ACTIVE, so the expired token is accepted. The code then performs a second verification using TokenVerifier.IS_ACTIVE to show the same token should be rejected under the fixed logic. There is no dependency on a live Keycloak server; the PoC is self-contained because the vulnerable helper accepts a public key directly. The main fingerprintable values are the REST path /exploit/attack, the local service URL http://localhost:8080/exploit/attack used in the README, the hardcoded issuer http://keycloak.example/realms/demo, and port 8080 exposed by the application/container. Repository structure and purpose: - pom.xml: Maven/Spring Boot project definition; pulls in spring-boot-starter-web, vulnerable camel-keycloak 4.18.2, and keycloak-core 26.0.8. - src/main/java/com/example/Application.java: standard Spring Boot entry point. - src/main/java/com/example/ExploitController.java: core exploit logic and HTTP endpoint. - src/main/resources/application.properties: sets server.port=8080. - Dockerfile and docker-compose.yml: package and run the reproducer as a containerized web service. - README.md: detailed vulnerability explanation, affected/fixed versions, reproduction steps, and expected output. Overall, this is a valid operational PoC for demonstrating acceptance of expired or not-yet-valid access tokens in affected Apache Camel camel-keycloak versions when routes rely on KeycloakSecurityHelper.parseAndVerifyAccessToken.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.