Junglewise Threat Intelligence

CVE-2026-19607: Keycloak first-broker-login account collision flaw

CVE-2026-19607 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Executive brief

Keycloak is an open-source identity and access management system used to authenticate users and manage access to applications. A flaw in its external identity provider login flow allows an attacker to register a matching username on an external provider to cause a username collision, locking legitimate users out of their Keycloak accounts.

Technical details

A vulnerability exists in the first-broker-login flow of the keycloak-services component, which handles initial authentication and account linking for users logging in via external identity providers. An attacker can exploit this by registering a matching username on an external provider to trigger a username collision in Keycloak. The attack results in denial of service to the legitimate user, as they become locked out of their account. The vulnerability requires network access to an affected Keycloak instance and knowledge of target usernames, but does not require prior authentication. Patches are expected from the vendor.

Affected products

  • Keycloak Keycloak <UNKNOWN>

Timeline

  • 2026-09-16: disclosed

References

Related threats