Skip to content
VulniPulse
Advisory severityCritical9.8Apache Software Foundation

Critical [CVE-2026-23552 +1] Apache Camel: Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open')…

This critical-severity Apache Software Foundation advisory covers CVE-2026-53913 and CVE-2026-23552 affecting Apache Camel Keycloak.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations. This bulletin covers 2 CVEs; its score, affected versions and guidance may apply to different issues within that bulletin.

CVE-2026-53913 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Apache Software FoundationMessaging
Open source advisory

Android app · Google Play

Monitor future Apache Software Foundation CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.

The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty - validates the roles, and - only if requiredPermissions is non-empty - validates the permissions.

The actual cryptographic verification of the bearer access token (signature, issuer and expiry for a local JWT, or active-state and issuer for token introspection) is performed exclusively inside those role and permission checks.

KeycloakSecurityPolicy defaults requiredRoles and requiredPermissions to empty - which is the documented 'Basic Setup' - so on a route configured that way the role and permission checks are skipped and the access token is therefore never verified.

The token-presence check still rejects a missing token, but an invalid token is accepted: any non-null value in the Authorization: Bearer header - including an arbitrary string or a forged, unsigned JWT - passes the policy and the request reaches the protected route, with no signature, issuer or expiry check and no request to Keycloak.

Affected versions
  • 4.15.0 through 4.18.3
  • 4.19.0 through 4.21.0.

Official advisory · high-confidence parse· fetched 3 months ago·verify at source

Fixed versions
  • 4.21.0
  • 4.18.3

Official advisory · high-confidence parse· fetched 3 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Users are recommended to upgrade to version 4.21.0, which fixes the issue.
  • If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3.
  • For deployments that cannot upgrade immediately, configure a non-empty requiredRoles or requiredPermissions on every KeycloakSecurityPolicy so that the token-verification path is exercised, set allowTokenFromHeader to false where the token is not expected from the request header, or perform token verification at the framework layer ahead of the policy.

Official advisory · high-confidence parse· fetched 3 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.