Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9087

Опубликовано: 20 мая 2026
Источник: nvd
CVSS3: 6.4
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*

EPSS

Процентиль: 24%
0.00312
Низкий

6.4 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.4
redhat
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

CVSS3: 6.4
debian
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is ...

CVSS3: 6.4
github
2 месяца назад

Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise

EPSS

Процентиль: 24%
0.00312
Низкий

6.4 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-639