CVE-2026-9087

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-05-20 17:16

Updated : 2026-07-23 12:10


NVD link : CVE-2026-9087

Mitre link : CVE-2026-9087

CVE.ORG link : CVE-2026-9087


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-639

Authorization Bypass Through User-Controlled Key