Improper Authentication in Keycloak - CVE-2026-19607
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper authentication in the first-broker-login flow of the keycloak-services component when linking an account through an external identity provider. A remote attacker can register a matching username with an external identity provider to cause a denial of service.