Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-9087

Опубликовано: 20 мая 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 24%
0.00312
Низкий

Связанные уязвимости

CVSS3: 6.4
redhat
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

CVSS3: 6.4
nvd
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

CVSS3: 6.4
github
2 месяца назад

Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise

EPSS

Процентиль: 24%
0.00312
Низкий