Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the Keycloak first-broker-login flow within the keycloak-services Maven artifact. The vulnerability exists because the flow does not sufficiently validate or prevent a brokered identity from colliding with an existing local user's username when loginWithEmail is enabled and usernames are email-shaped. An unauthenticated remote attacker can register an account on a configured external Identity Provider using an email address that matches a victim's Keycloak username. By performing a broker login with this account, the attacker creates a username collision state. This state causes all subsequent authentication attempts by the legitimate victim to fail, effectively locking them out of their account.