CVE-2026-82968
Received Received - Intake

Keycloak Social Account Linking Authentication Bypass

Vulnerability report for CVE-2026-82968, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: redhat-SADP

Description

A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's first-broker-login flow. When a user links a social identity provider account to their local account, the verification proof is not properly tied to that specific identity. An attacker with a different account on the same social provider can exploit this to link their account to the victim's local profile and gain unauthorized access.

Detection Guidance

Detecting this vulnerability requires monitoring Keycloak's first-broker-login flow for unusual account-linking activities. Check Keycloak logs for multiple social provider account associations to the same local account. Look for events where a user's local account is linked to a different social identity than expected. Review authentication logs for suspicious cross-session verification proofs that are not bound to a specific upstream identity.

Impact Analysis

If exploited, an attacker could gain unauthorized access to your local account by linking their social identity to it. This could allow them to access your data and permissions. Exploitation requires specific timing and user interaction during an active account-linking process.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, which may violate GDPR's data protection requirements or HIPAA's access controls. Unauthorized account linking could expose personal or health information, potentially resulting in non-compliance with these regulations.

Mitigation Strategies

Upgrade Keycloak to the latest version if available. If no upgrade is available, disable the first-broker-login flow or restrict social identity provider account linking to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82968. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart