CVE-2026-9087: Keycloak: cross-session email verification proof not bound to upstream identity in first-broker-login
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9087?
CVE-2026-9087 is classified as a moderate severity vulnerability affecting Keycloak.
How do I fix CVE-2026-9087?
To fix CVE-2026-9087, update Keycloak to the latest version that addresses this vulnerability.
What impact does CVE-2026-9087 have on users?
CVE-2026-9087 allows for potential cross-session verification issues, which may compromise user authentication trust.
Which versions of Keycloak are affected by CVE-2026-9087?
CVE-2026-9087 affects multiple versions of Keycloak, and users should check for specific version disclosures in advisories.
Is there a workaround for CVE-2026-9087?
Currently, there are no known effective workarounds for CVE-2026-9087 other than applying the fix by updating Keycloak.