Account Takeover Vulnerability in Keycloak Open-Source Identity Management
CVE-2026-15571

7.3HIGH

What is CVE-2026-15571?

A flaw exists in the account-linking endpoint of Keycloak, a widely utilized open-source identity and access management system. This vulnerability enables an attacker to exploit a predictable mechanism used to protect the account-linking process, potentially allowing them to forge valid linking URLs. By leveraging social engineering to trick users into authenticating through a malicious OIDC client, attackers can associate the victim's account with their external identity. This may lead to full control of the victim’s account, resulting in unauthorized access and manipulation.

Affected Version(s)

Red Hat build of Keycloak 26.6 26.6.6-1

Red Hat build of Keycloak 26.6 26.6-12

Red Hat build of Keycloak 26.6 26.6-12

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank yd1ng for reporting this issue.
.