Junglewise Threat Intelligence

CVE-2026-7507: Keycloak session fixation in login-actions endpoints

CVE-2026-7507 · Severity: high · CVSS 7.5 · Published 2026-05-19

Technologies: Red Hat build of Keycloak, Red Hat build of Keycloak, org.keycloak:keycloak-services (Maven), Keycloak-Services. Vendors: Red Hat, Maven, Keycloak.

Executive brief

Keycloak, a popular identity and access management solution, is vulnerable to a session fixation flaw that could allow an attacker to take over user accounts. By tricking a victim into clicking a malicious link, an attacker can hijack the login process and gain access to the victim's account without needing their password. This could lead to a complete compromise of sensitive data or administrative control over the entire authentication system.

Technical details

A session fixation vulnerability exists in Keycloak's login-actions endpoints, specifically within the /login-actions/restart component. The endpoint processes session handles without sufficient CSRF protection or cookie ownership validation, allowing an unauthenticated attacker to pre-create an authentication session and reset its state. When a victim visits a maliciously crafted link, Single Sign-On (SSO) may transparently authenticate them, allowing the attacker to hijack 'required-action' forms. This can result in full account takeover, including administrative accounts in the master realm. The vulnerability is patched in Keycloak version 26.6.2 and corresponding Red Hat builds.

Affected products

  • Keycloak keycloak-services < 26.6.2
  • Red Hat Red Hat build of Keycloak 26.4.x < 26.4.12, 26.2.x < 26.2.16

Timeline

  • 2026-04-30: other: Reported to Red Hat Bugzilla
  • 2026-05-19: advisory: GitHub Advisory and NVD publication
  • 2026-05-20: patched: Red Hat released security updates (RHSA-2026:19594)

References

Related threats