Detects Keycloak instances where the parseInvitationToken function decodes organization invitation JWTs without verifying their cryptographic signature. Versions before 26.2.13, 26.4.9, and 26.5.3 are affected. An attacker can modify the organization ID and email in a legitimate invitation token to register into any organization.
Is your app exploitable through CVE-2026-1529?
Scan your domain free