QSearchQSearch

CVE-2026-7507

7.5 HIGH

A session fixation vulnerability was found in Keycloak's login-actions endpoints

Published: 2026-05-19 · Last updated: 2026-06-03

Severity and scoring

CVSS
7.5 HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE
CWE-290

Affected products

VendorProduct
redhatbuild_of_keycloak

Description

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection or cookie ownership validation—an attacker can reset the authentication flow state. This causes Single Sign-On (SSO) to authenticate the victim transparently upon clicking the link, allowing the attacker to hijack the required-action form without needing the victim's credentials. A successful exploit could lead to complete account takeover, including highly privileged administrative accounts.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-1767 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component (5.6 MEDIUM)
  • CVE-2026-1766 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 com... (5.6 MEDIUM)
  • CVE-2026-11793 A stack buffer overflow flaw was found in 389 Directory Server (4.9 MEDIUM)
  • CVE-2026-11790 A flaw was found in 389 Directory Server (4.9 MEDIUM)
  • CVE-2026-11789 A flaw was found in 389 Directory Server (4.9 MEDIUM)

Same CWE

  • CVE-2026-53857 OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowF... (8.1 HIGH)
  • CVE-2026-53849 OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account i... (8.1 HIGH)
  • CVE-2026-42662 Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions (6.5 MEDIUM)
  • CVE-2026-27089 Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions (7.5 HIGH)
  • CVE-2026-36537 ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange (9.8 CRITICAL)