Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9087

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 6.4

Описание

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

Отчет

Important: A flaw in Keycloak's cross-session email verification allows an attacker to gain persistent access to a victim's local account. This occurs when an attacker controls an upstream identity provider account sharing an email with the victim, and the victim is actively linking their account while email verification is enabled and the identity provider is configured with trustEmail=false. The attacker can then consume the verification proof, linking their account to the victim's.

Меры по смягчению последствий

To mitigate this issue, configure the affected identity provider to set trustEmail=true. This ensures that Keycloak trusts the email address provided by the upstream identity provider, bypassing the vulnerable verification flow. This mitigation should only be applied if the upstream identity provider is fully trusted to verify email addresses and prevent malicious account creation with existing email addresses. Configuration changes may require a Keycloak service restart or reload to take effect.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2480172keycloak: Cross-Session Email Verification Proof Not Bound to Upstream Identity in First-Broker-Login

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
nvd
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

CVSS3: 6.4
debian
2 месяца назад

A flaw was found in Keycloak. The cross-session verification proof is ...

CVSS3: 6.4
github
2 месяца назад

Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise

6.4 Medium

CVSS3