Session fixation in Keycloak - CVE-2025-12390
Published: November 18, 2025
Vulnerability identifier: #VU118575
CSH Severity: Low
CVSS v4: 6.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2025-12390
CWE-ID: CWE-384
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to another session.
The vulnerability exists due to accidental session identifier reuse when logging in on the same device. A local user can get access to another user's session if both use the same device and browser.
Affected software
Keycloak
Red Hat build of Keycloak
Red Hat build of Keycloak
How to mitigate CVE-2025-12390
Install updates from vendor's website.
Keycloak - update to 26.4.4
Red Hat build of Keycloak - update to 26.4.4
Red Hat build of Keycloak - update to 26.4.4