Incorrect Comparison in Keycloak - CVE-2026-90997

 

Incorrect Comparison in Keycloak - CVE-2026-90997

Published: September 18, 2026 / Updated: September 18, 2026


Vulnerability identifier: #VU150790
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90997
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to the token endpoint or login flow.

The vulnerability exists due to a mismatch in row-count semantics between the database driver and Keycloak's application logic in Keycloak's replay protection mechanism when processing intercepted single-use security artifacts. A remote attacker can replay an intercepted JWT client assertion, DPoP proof, or one-time password code to gain unauthorized access to the token endpoint or login flow.

Only Keycloak deployments operating in stateless mode with MySQL or MariaDB are affected.


Affected software

Keycloak

How to mitigate CVE-2026-90997

Install security update from vendor's website.

Keycloak - update to 26.7.4

External References

Related Security Bulletins