CVE-2026-92358: Keycloak-services: keycloak-services: residual cross-browser account-link proof allows silent re-linking
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is established or when the user later manually removes the link. An attacker who controls the external identity can exploit this leftover proof to silently re-establish the link and gain unauthorized access to the victims account without any further confirmation.
Affected Software
Event History
Frequently Asked Questions
Which accounts are exposed to this issue?
Accounts using Keycloak’s first broker login flow can be exposed when an account-linking request is confirmed from a different browser, causing a temporary proof to be created. The risk persists if that proof remains after linking or after the user manually removes the link.
What does an attacker need to exploit the issue?
The attacker must control the external identity involved in the account link and be able to use the leftover proof. They can then silently re-establish the link and access the victim’s account without another confirmation.