Bug 2534997 (CVE-2026-92358)

Summary: CVE-2026-92358 keycloak-services: keycloak-services: Residual cross-browser account-link proof allows silent re-linking
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aschwart, aszczucz, boliveir, drichtar, mposolda, pjindal, rmartinc, ssilvert, sthorger, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is established or when the user later manually removes the link. An attacker who controls the external identity can exploit this leftover proof to silently re-establish the link and gain unauthorized access to the victims account without any further confirmation.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-16 05:21:15 UTC
A flaw was found in Keycloaks first broker login flow. When a user confirms an identity provider account-link request from a different browser context, Keycloak generates a server-side single-use proof to facilitate the cross-session completion. This proof is not invalidated when the original authentication session successfully completes the link, nor is it revoked when the user subsequently removes the identity provider link via the Account self-service API.
An attacker who controls the upstream identity can exploit this residual proof by initiating a fresh broker login before the proof expires (default 300 seconds). Successful exploitation allows the attacker to silently restore a previously removed federated link and authenticate as the victim without requiring new email confirmation. This issue is a follow-on to CVE-2026-9087 and represents an incomplete fix/bypass of the original vulnerability.