Executive brief
Keycloak, a popular identity and access management solution, is vulnerable to a session fixation flaw that could allow an attacker to take over user accounts. By tricking a victim into clicking a malicious link, an attacker can hijack the login process and gain access to the victim's account without needing their password. This could lead to a complete compromise of sensitive data or administrative control over the entire authentication system.
Technical details
A session fixation vulnerability exists in Keycloak's login-actions endpoints, specifically within the /login-actions/restart component. The endpoint processes session handles without sufficient CSRF protection or cookie ownership validation, allowing an unauthenticated attacker to pre-create an authentication session and reset its state. When a victim visits a maliciously crafted link, Single Sign-On (SSO) may transparently authenticate them, allowing the attacker to hijack 'required-action' forms. This can result in full account takeover, including administrative accounts in the master realm. The vulnerability is patched in Keycloak version 26.6.2 and corresponding Red Hat builds.
Affected products
- Keycloak keycloak-services < 26.6.2
- Red Hat Red Hat build of Keycloak 26.4.x < 26.4.12, 26.2.x < 26.2.16
Timeline
- 2026-04-30: other: Reported to Red Hat Bugzilla
- 2026-05-19: advisory: GitHub Advisory and NVD publication
- 2026-05-20: patched: Red Hat released security updates (RHSA-2026:19594)