A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
History

Wed, 02 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 02 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
Title Keycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providers
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-639
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-02T13:00:51.029Z

Reserved: 2026-08-31T14:07:24.652Z

Link: CVE-2026-82968

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T02:17:19.750

Modified: 2026-09-02T13:18:13.947

Link: CVE-2026-82968

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-27T10:19:11Z

Links: CVE-2026-82968 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:30:06Z