Predictable from Observable State in Keycloak - CVE-2026-15571
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to take over a victim\'s account.
The vulnerability exists due to predictable hash generation in the legacy client-initiated account-linking endpoint when processing account-linking requests. A remote user can trick a user into authenticating and forge a valid linking URL to connect the victim\'s account to an attacker-controlled external identity to take over a victim\'s account.
User interaction is required to authenticate.