CVE-2026-4325: Keycloak: keycloak: replay of action tokens via improper handling of single-use entries
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise.
Other sources
Keycloak's SingleUseObjectProvider is a global flat key-value store used without type or namespace isolation. This allows an attacker to delete arbitrary single-use entries, enabling the replay of consumed action tokens such as password reset links. Requirements to exploit:
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4325?
CVE-2026-4325 is classified as a critical vulnerability due to its potential to allow unauthorized deletion of single-use entries.
How do I fix CVE-2026-4325?
To mitigate CVE-2026-4325, it is recommended to upgrade Keycloak to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-4325?
The impact of CVE-2026-4325 includes the possibility for attackers to exploit the vulnerability to delete critical single-use action tokens.
Which versions of Keycloak are affected by CVE-2026-4325?
CVE-2026-4325 affects various versions of Red Hat Keycloak, including 26.2, 26.2.15, 26.4, and 26.4.11.
Is there a workaround for CVE-2026-4325?
As of now, there are no confirmed workarounds for CVE-2026-4325, and patching to a secure version is strongly advised.