Flaw in Account Linking Process of Keycloak Affects User Security
CVE-2026-92358
6.4MEDIUM
What is CVE-2026-92358?
A security flaw exists in the account-linking process of Keycloak, where a temporary proof intended for validation is not properly cleared after the link is established. This oversight allows an attacker, controlling the external identity, to exploit the leftover proof to silently re-establish the link. As a result, the attacker can gain unauthorized access to the victim's account without needing any further confirmation, posing a significant risk to user accounts.
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank He Wei(ギカク) for reporting this issue.