Authentication Bypass by Spoofing in Keycloak - CVE-2026-7507

 

Authentication Bypass by Spoofing in Keycloak - CVE-2026-7507

Published: September 10, 2026


Vulnerability identifier: #VU148949
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-7507
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over accounts.

The vulnerability exists due to authentication bypass by spoofing in Keycloak login-actions endpoints when processing a crafted link to the /login-actions/restart endpoint. A remote attacker can pre-create an authentication session and trick a victim into visiting the crafted link to take over accounts.

User interaction is required to visit the crafted link.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-7507

Install security update from vendor's website.

Keycloak - update to 26.6.2
Red Hat build of Keycloak - addressed in versions 26.2.16, 26.4.12

External References

Related Security Bulletins