Flaw in Account Linking Process of Keycloak Affects User Security
CVE-2026-92358

6.4MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92358?

A security flaw exists in the account-linking process of Keycloak, where a temporary proof intended for validation is not properly cleared after the link is established. This oversight allows an attacker, controlling the external identity, to exploit the leftover proof to silently re-establish the link. As a result, the attacker can gain unauthorized access to the victim's account without needing any further confirmation, posing a significant risk to user accounts.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank He Wei(ギカク) for reporting this issue.
.