Bug 2534997 (CVE-2026-92358) - CVE-2026-92358 keycloak-services: keycloak-services: Residual cross-browser account-link proof allows silent re-linking
Summary: CVE-2026-92358 keycloak-services: keycloak-services: Residual cross-browser a...
Keywords:
Status: NEW
Alias: CVE-2026-92358
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-16 05:21 UTC by OSIDB Bzimport
Modified: 2026-09-16 05:21 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-16 05:21:15 UTC
A flaw was found in Keycloaks first broker login flow. When a user confirms an identity provider account-link request from a different browser context, Keycloak generates a server-side single-use proof to facilitate the cross-session completion. This proof is not invalidated when the original authentication session successfully completes the link, nor is it revoked when the user subsequently removes the identity provider link via the Account self-service API.
An attacker who controls the upstream identity can exploit this residual proof by initiating a fresh broker login before the proof expires (default 300 seconds). Successful exploitation allows the attacker to silently restore a previously removed federated link and authenticate as the victim without requiring new email confirmation. This issue is a follow-on to CVE-2026-9087 and represents an incomplete fix/bypass of the original vulnerability.


Note You need to log in before you can comment on or make changes to this bug.