Junglewise Threat Intelligence

CVE-2026-82968: Keycloak first-broker-login authorization bypass in social identity linking

CVE-2026-82968 · Severity: medium · CVSS 6.4 · Published 2026-09-02

Technologies: Red Hat Keycloak. Vendors: Red Hat.

Executive brief

Keycloak is an open-source identity management system used by organizations to manage user authentication and account linking across multiple identity providers. A flaw in the social identity account linking process allows an attacker with access to the same social provider to intercept and link their account to a victim's local account, gaining full access to the victim's data and permissions within the system.

Technical details

The vulnerability exists in Keycloak's first-broker-login flow during social identity provider account linking. The verification proof generated when linking a social account to a local account is not strictly bound to the specific upstream identity being verified, enabling cross-session account takeover (CWE-639). An attacker with an account on the same social provider can intercept the linking process and redirect it to bind their own identity to the victim's local account. Exploitation requires network access to the Keycloak instance, an existing attacker account on the target social provider, low privileges (authenticated account), and specific timing during the victim's active account-linking session. Successful exploitation grants the attacker complete unauthorized access to the victim's local account, including their data and associated permissions. No mitigation is currently available according to Red Hat Product Security; patches are pending.

Affected products

  • Red Hat Keycloak

Timeline

  • 2026-09-02: disclosed

References