Junglewise Threat Intelligence

CVE-2026-9087: Keycloak authorization bypass in First-Broker-Login flow

CVE-2026-9087 · Severity: medium · CVSS 6.4 · Published 2026-05-20

Technologies: org.keycloak:keycloak-services (Maven), Keycloak. Vendors: Maven, Keycloak.

Executive brief

Keycloak is an open-source identity and access management solution used to secure applications and manage user logins. A security flaw in its account linking process could allow an attacker to take over a user's local account by linking it to a different social or external identity provider account. This could lead to unauthorized access to sensitive user data and corporate resources.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Keycloak's 'First-Broker-Login' flow. The cross-session verification proof used during identity provider (IdP) account linking is keyed only by the local userId and idpAlias, but is not cryptographically bound to the specific upstream identity being verified. A remote attacker with an account on the same upstream IdP can exploit this lack of binding to consume the verification proof intended for a victim, successfully linking their own upstream identity to the victim's local Keycloak account. This requires network access and some user interaction. The issue is fixed in version 26.6.3 by including the external ID in the verification object key.

Affected products

  • Keycloak Keycloak < 26.6.3

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory
  • 2026-06-02: patched: Fix committed to repository
  • 2026-06-10: patched: Red Hat build of Keycloak 26.6.3 released

References

Related threats