Bug 2514529 (CVE-2026-19607)

Summary: CVE-2026-19607 keycloak-services: keycloak-services: Broker-originated username collision causes account lockout
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aschwart, aszczucz, boliveir, drichtar, mposolda, pjindal, rmartinc, security-response-team, ssilvert, sthorger, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-11-09   

Description OSIDB Bzimport 2026-08-12 08:42:39 UTC
A flaw was found in the Keycloak first-broker-login flow within the keycloak-services Maven artifact. The vulnerability exists because the flow does not sufficiently validate or prevent a brokered identity from colliding with an existing local user's username when loginWithEmail is enabled and usernames are email-shaped. An unauthenticated remote attacker can register an account on a configured external Identity Provider using an email address that matches a victim's Keycloak username. By performing a broker login with this account, the attacker creates a username collision state. This state causes all subsequent authentication attempts by the legitimate victim to fail, effectively locking them out of their account.