Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-53913
Apache Camel: camel-keycloak accepts any bearer token when no roles or permissions are required
Technology
Apache Camel
CVSS Score
9.8 / 10.0
Affected Versions
4.15.0 before 4.18.3; 4.19.0 before 4.21.0
Upstream Fix
4.18.3; 4.21.0
Published
July 6, 2026
OSSeva Coverage
Fixed upstream
Description
KeycloakSecurityPolicy verified the bearer token only inside its role and permission checks. With no required roles or permissions, which is the default, the token was never verified and any non-empty bearer value was accepted. Rated high by the Camel project. Fixed in 4.18.3 and 4.21.0.
Is your Apache Camel deployment affected?
If you're running 4.15.0 before 4.18.3; 4.19.0 before 4.21.0, you need this patch. Book a discovery call to get covered.