Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-53913.
Unlock with Pro - from £29/user/moDetect Apache Camel camel-keycloak KeycloakSecurityPolicy Authentication Bypass (CVE-2026-53913) in Google Chronicle
Apache Camel's camel-keycloak component contains a KeycloakSecurityPolicy that improperly handles authentication (CWE-287), resulting in missing authentication for a critical function and a fail-open condition. Affected versions >=4.15.0 <4.18.3 and >=4.19.0 <4.21.0 allow requests to bypass Keycloak-enforced authentication checks on Camel routes, permitting unauthenticated access to protected endpoints/routes. CVSS 9.8, PoC public via GHSA-qvc3-6q9x-95pj.
MITRE ATT&CK
YARA-L Detection Query
rule camel_keycloak_auth_bypass_cve_2026_53913 {
meta:
description = "Detects unauthenticated successful access to Keycloak-protected Apache Camel routes indicative of CVE-2026-53913"
severity = "CRITICAL"
cve = "CVE-2026-53913"
events:
$e.metadata.event_type = "NETWORK_HTTP"
$e.target.url = /(secured|admin|protected)/ nocase
$e.network.http.response_code = 200 or $e.network.http.response_code = 201 or $e.network.http.response_code = 202 or $e.network.http.response_code = 204
$e.network.http.authorization = ""
$e.principal.ip = $ip
match:
$ip over 5m
condition:
#e >= 3
} Detects a burst of successful HTTP responses to Keycloak-protected Camel routes with no Authorization header present, indicating the fail-open bypass condition.
Data Sources
Required Tables
False Positives & Tuning
- Health-check endpoints intentionally unauthenticated
- Proxy logs that strip auth headers before ingestion
- mTLS-only internal service traffic
- Authorized vulnerability scans
Other platforms for CVE-2026-53913
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Simulate unauthenticated request to Keycloak-protected Camel route
Expected signal: Application/access log entry showing a request to /secured/test-endpoint with no Authorization header and an HTTP 200-series response.
- Test 2Repeated bypass attempts to trigger threshold-based alerting
Expected signal: Five sequential log entries within a 5-minute window from the same client IP hitting /admin/config without Authorization headers, each returning 2xx.
- Test 3Windows-based PowerShell simulation of unauthenticated access
Expected signal: Access log entry recording a request to /protected/data with an empty Authorization header field and a successful HTTP status code.
Unlock playbooks & atomic tests with Pro
Get the full detection package for CVE-2026-53913 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.
df00tech Pro — £29/user/month