Junglewise Threat Intelligence

CVE-2026-92358: Keycloak account-linking proof improper clearance

CVE-2026-92358 · Severity: medium · CVSS 6.4 · Published 2026-09-16

Technologies: Red Hat Keycloak. Vendors: Red Hat.

Executive brief

Keycloak, an identity and access management platform, contains a flaw in its first broker login flow that fails to properly clear temporary proof tokens used for account linking across browsers. An attacker controlling an external identity provider can exploit leftover proof tokens to silently re-establish links to victims' accounts and gain unauthorized access, even after the user has manually removed the link, bypassing confirmation steps.

Technical details

The vulnerability exists in Keycloak's first broker login flow where temporary proof tokens are created to validate cross-browser account linking requests. The root cause is insufficient session expiration (CWE-613): the proof is not consumed or revoked after successful linking or when users manually unlink accounts. An attacker with control of an external identity provider can reuse the leftover proof to silently re-establish account links. Exploitation requires the attacker to control the external identity, have low privileges on the Keycloak instance, and requires user interaction (a short time window before server-side proof expires). Successful exploitation allows unauthorized account access without additional confirmation. No mitigation options meeting Red Hat's criteria are currently available; patching when released is recommended.

Affected products

  • Red Hat Keycloak <UNKNOWN>

Timeline

  • 2026-09-16: disclosed

References