Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15571

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it enables full account takeover through a predictable security hash. Successful exploitation allows an attacker to link an unauthorized identity to a victim's account and subsequently impersonate that user across the realm. The vulnerability's root cause is the use of predictable session identifiers and client-known metadata in the construction of the account-linking CSRF protection hash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleFixedRHSA-2026:5652418.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9FixedRHSA-2026:5652418.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9-operatorFixedRHSA-2026:5652418.08.2026
Red Hat build of Keycloak 26.6.6keycloak-servicesFixedRHSA-2026:5652318.08.2026
Red Hat build of Keycloak 26.6.6rhbk/keycloak-rhel9FixedRHSA-2026:5652318.08.2026
Red Hat build of Keycloak 26.6.6rhbk-openshift-rhel9/rhbk-openshift-rhel9FixedRHSA-2026:5652318.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-341
https://bugzilla.redhat.com/show_bug.cgi?id=2499591keycloak-services: keycloak-services: Predictable account-linking hash enables account takeover via malicious OIDC client

EPSS

Процентиль: 24%
0.00309
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
5 дней назад

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.

CVSS3: 7.3
debian
5 дней назад

A flaw was found in the legacy client-initiated account-linking endpoi ...

CVSS3: 7.3
github
5 дней назад

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.

EPSS

Процентиль: 24%
0.00309
Низкий

7.3 High

CVSS3