CVE-2026-92358: Insufficient Session Expiration in Red Hat Red Hat Build of Keycloak
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is established or when the user later manually removes the link. An attacker who controls the external identity can exploit this leftover proof to silently re-establish the link and gain unauthorized access to the victims account without any further confirmation.
CVE-2026-92358: Insufficient Session Expiration in Red Hat Red Hat Build of Keycloak
Description
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after the link is established or when the user later manually removes the link. An attacker who controls the external identity can exploit this leftover proof to silently re-establish the link and gain unauthorized access to the victims account without any further confirmation.
CVSS v3.1
Score 6.4medium
Affected software
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat Build of Keycloak
Red Hat
Red Hat Single Sign-On 7
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-16T05:20:49.719Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-92358","vendor":"Red Hat"}]
Threat ID: 6aaa32e555bf5e2cf517fb64
Added to database: 09/16/2026, 06:10:45 UTC
Last updated: 09/16/2026, 06:10:45 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.