Keycloak: Unauthorized account takeover via WebAuthn token replay
Moderate severity
GitHub Reviewed
Published
May 19, 2026
to the GitHub Advisory Database
•
Updated Jun 4, 2026
Description
Published by the National Vulnerability Database
May 19, 2026
Published to the GitHub Advisory Database
May 19, 2026
Reviewed
Jun 4, 2026
Last updated
Jun 4, 2026
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay
ExecuteActionsActionTokentokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.References