CVE-2026-82968: Keycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providers
A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What access and conditions does exploitation require?
The attack is network-reachable but requires low-level privileges and user interaction. It also has high attack complexity and requires the attacker to have a different account with the same social identity provider involved in the linking flow.
What is the likely impact if the attack succeeds?
An attacker can link their social-provider account to the victim’s local profile and gain unauthorized access to that local account. The reported impact includes high confidentiality and integrity effects, with no availability impact.