Identity Management Service Vulnerability in Keycloak by Red Hat
CVE-2026-82968
6.4MEDIUM
What is CVE-2026-82968?
A security flaw exists in Keycloak's first-broker-login process, where the verification proof for linking social identity provider accounts is inadequately constrained. This vulnerability allows an attacker with access to a different account on the same social provider to potentially link their malicious account to a victim's local profile, thereby obtaining unauthorized access to the victim's account.
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank He Wei(ギカク) for reporting this issue.