AIA (Application-initiated actions) could be used to circumvent required actions configured by an administrator to be performed by a user upon signing in. This could lead to the user circumventing requirements such as setting up 2FA. - A user account that has been required by an administrator to perform a required action. - The same user passing in a URL parameter during the sign in process.
This issue has been addressed in the following products: Red Hat build of Keycloak 22 Via RHSA-2025:4336 https://access.redhat.com/errata/RHSA-2025:4336
This issue has been addressed in the following products: Red Hat build of Keycloak 26.0 Via RHSA-2025:4335 https://access.redhat.com/errata/RHSA-2025:4335