CVE-2026-92358: Keycloak-services: keycloak-services: residual cross-browser account-link proof allows silent re-linking

Published Sep 16, 2026
·
Updated

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is established or when the user later manually removes the link. An attacker who controls the external identity can exploit this leftover proof to silently re-establish the link and gain unauthorized access to the victims account without any further confirmation.

Affected Software

1 affected component
Keycloak keycloak-services

Event History

Sep 16, 2026
CVE Published
via MITRE·05:50 AM
Data Sourced
via MITRE·05:50 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which accounts are exposed to this issue?

Accounts using Keycloak’s first broker login flow can be exposed when an account-linking request is confirmed from a different browser, causing a temporary proof to be created. The risk persists if that proof remains after linking or after the user manually removes the link.

2

What does an attacker need to exploit the issue?

The attacker must control the external identity involved in the account link and be able to use the leftover proof. They can then silently re-establish the link and access the victim’s account without another confirmation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203