Authorization bypass through user-controlled key in Keycloak - CVE-2026-9087
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to compromise a victim\'s local account.
The vulnerability exists due to insufficient verification proof scoping in the cross-session verification proof mechanism when linking identity provider accounts. A remote user can use a verification proof for a victim\'s local account to link a second upstream account on the same identity provider and compromise a victim\'s local account.
User interaction is required.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-9087
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3