Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-53913

Apache Camel: camel-keycloak accepts any bearer token when no roles or permissions are required

Technology

Apache Camel

CVSS Score

9.8 / 10.0

Affected Versions

4.15.0 before 4.18.3; 4.19.0 before 4.21.0

Upstream Fix

4.18.3; 4.21.0

Published

July 6, 2026

OSSeva Coverage

Fixed upstream

Description

KeycloakSecurityPolicy verified the bearer token only inside its role and permission checks. With no required roles or permissions, which is the default, the token was never verified and any non-empty bearer value was accepted. Rated high by the Camel project. Fixed in 4.18.3 and 4.21.0.

Upstream record: NVD · CVE.org

Is your Apache Camel deployment affected?

If you're running 4.15.0 before 4.18.3; 4.19.0 before 4.21.0, you need this patch. Book a discovery call to get covered.