Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in Keycloaks first broker login flow. When a user confirms an identity provider account-link request from a different browser context, Keycloak generates a server-side single-use proof to facilitate the cross-session completion. This proof is not invalidated when the original authentication session successfully completes the link, nor is it revoked when the user subsequently removes the identity provider link via the Account self-service API. An attacker who controls the upstream identity can exploit this residual proof by initiating a fresh broker login before the proof expires (default 300 seconds). Successful exploitation allows the attacker to silently restore a previously removed federated link and authenticate as the victim without requiring new email confirmation. This issue is a follow-on to CVE-2026-9087 and represents an incomplete fix/bypass of the original vulnerability.