Vulnerability Description
A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-82968
- https://bugzilla.redhat.com/show_bug.cgi?id=2526318
FAQ
What is CVE-2026-82968?
CVE-2026-82968 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generat...
How severe is CVE-2026-82968?
CVE-2026-82968 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82968?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.