A flaw was found in Keycloak. The cross-session...
Moderate severity
Unreviewed
Published
May 20, 2026
to the GitHub Advisory Database
•
Updated May 20, 2026
Description
Published by the National Vulnerability Database
May 20, 2026
Published to the GitHub Advisory Database
May 20, 2026
Last updated
May 20, 2026
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId,
idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.
References