CVE-2026-53913
Apache Software Foundation Apache Camel Keycloak, camel
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty - validates the roles, and - only if requiredPermissions is non-empty - validates the permissions. The actual cryptographic verification of the bearer access token (signature, issuer and exp...
- CVSS
- 9.8
- EPSS
- 0.75% 51.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.06