CVE-2026-15571
A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.33%
- CWE
- CWE-341
- Published
- 2026-08-18
- Last modified
- 2026-08-20
Affected products
- Red Hat Red Hat build of Keycloak 26.6
- Red Hat Red Hat build of Keycloak 26.6
Weakness type
Related vulnerabilities
- CVE-2026-19565 — Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey
- CVE-2026-42365 — GeoVision LPC2011/LPC2211 Web Interface guessable session cookie vulnerability
- CVE-2025-40780 — Cache poisoning due to weak PRNG
- CVE-2025-42925 — Predictable Object Identifier vulnerability in SAP NetWeaver AS Java (IIOP Service)
- CVE-2024-10141 — jsbroks COCO Annotator Session predictable state
- CVE-2023-49259 — Bruteforcing authentication cookie for a given user
- CVE-2021-4277 — fredsmith utils Filename screenshot_sync predictable state
- CVE-2020-5365 — Dell EMC Isilon versions 8.2.2 and earlier contain a remotesupport vulnerability. The...