All verified exploits

CVE-2026-1529 Organization Invitation Token Signature Bypass

Deterministic high Keycloak Added cve-verified-cve-2026-1529

Detects Keycloak instances where the parseInvitationToken function decodes organization invitation JWTs without verifying their cryptographic signature. Versions before 26.2.13, 26.4.9, and 26.5.3 are affected. An attacker can modify the organization ID and email in a legitimate invitation token to register into any organization.

Is your app exploitable through CVE-2026-1529?

Scan your domain free