Authentication Bypass by Spoofing in Keycloak - CVE-2026-7507
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to take over accounts.
The vulnerability exists due to authentication bypass by spoofing in Keycloak login-actions endpoints when processing a crafted link to the /login-actions/restart endpoint. A remote attacker can pre-create an authentication session and trick a victim into visiting the crafted link to take over accounts.
User interaction is required to visit the crafted link.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-7507
Red Hat build of Keycloak - addressed in versions 26.2.16, 26.4.12