CVE-2026-4325: Keycloak: keycloak: replay of action tokens via improper handling of single-use entries

Published Mar 17, 2026
·
Updated

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of consumed action tokens, such as password reset links. This could lead to unauthorized access or account compromise.

Other sources

Keycloak's SingleUseObjectProvider is a global flat key-value store used without type or namespace isolation. This allows an attacker to delete arbitrary single-use entries, enabling the replay of consumed action tokens such as password reset links. Requirements to exploit:

Red Hat

Affected Software

6 affected components
Red Hat Keycloak
redhat Build Of Keycloak
redhat Build Of Keycloak=26.2
redhat Build Of Keycloak=26.2.15
redhat Build Of Keycloak=26.4
redhat Build Of Keycloak=26.4.11

Event History

Mar 17, 2026
Data Sourced
via Red Hat·12:46 PM
DescriptionSeverityAffected Software
Apr 2, 2026
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-4325?

CVE-2026-4325 is classified as a critical vulnerability due to its potential to allow unauthorized deletion of single-use entries.

2

How do I fix CVE-2026-4325?

To mitigate CVE-2026-4325, it is recommended to upgrade Keycloak to the latest version that addresses this vulnerability.

3

What are the potential impacts of CVE-2026-4325?

The impact of CVE-2026-4325 includes the possibility for attackers to exploit the vulnerability to delete critical single-use action tokens.

4

Which versions of Keycloak are affected by CVE-2026-4325?

CVE-2026-4325 affects various versions of Red Hat Keycloak, including 26.2, 26.2.15, 26.4, and 26.4.11.

5

Is there a workaround for CVE-2026-4325?

As of now, there are no confirmed workarounds for CVE-2026-4325, and patching to a secure version is strongly advised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203