Account Takeover Vulnerability in Keycloak Open-Source Identity Management
CVE-2026-15571
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-15571?
A flaw exists in the account-linking endpoint of Keycloak, a widely utilized open-source identity and access management system. This vulnerability enables an attacker to exploit a predictable mechanism used to protect the account-linking process, potentially allowing them to forge valid linking URLs. By leveraging social engineering to trick users into authenticating through a malicious OIDC client, attackers can associate the victim's account with their external identity. This may lead to full control of the victim’s account, resulting in unauthorized access and manipulation.
Affected Version(s)
Red Hat build of Keycloak 26.6 26.6.6-1
Red Hat build of Keycloak 26.6 26.6-12
Red Hat build of Keycloak 26.6 26.6-12
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved