Количество 4
Количество 4
CVE-2026-9087
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.
CVE-2026-9087
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.
CVE-2026-9087
A flaw was found in Keycloak. The cross-session verification proof is ...
GHSA-m6qj-3mpp-57v8
Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9087 A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account. | CVSS3: 6.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-9087 A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account. | CVSS3: 6.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-9087 A flaw was found in Keycloak. The cross-session verification proof is ... | CVSS3: 6.4 | 0% Низкий | 2 месяца назад | |
GHSA-m6qj-3mpp-57v8 Keycloak: Insufficient verification proof scoping enables identity provider account linking attack and account compromise | CVSS3: 6.4 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу