{
  "threat_severity" : "Important",
  "public_date" : "2026-08-18T19:41:18Z",
  "bugzilla" : {
    "description" : "keycloak-services: keycloak-services: Predictable account-linking hash enables account takeover via malicious OIDC client",
    "id" : "2499591",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2499591"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-341",
  "details" : [ "A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.", "A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim." ],
  "statement" : "The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it enables full account takeover through a predictable security hash. Successful exploitation allows an attacker to link an unauthorized identity to a victim's account and subsequently impersonate that user across the realm. The vulnerability's root cause is the use of predictable session identifiers and client-known metadata in the construction of the account-linking CSRF protection hash.",
  "acknowledgement" : "Red Hat would like to thank yd1ng for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:56524",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-operator-bundle:26.6.6-1"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:56524",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-rhel9:26.6-12"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:56524",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-rhel9-operator:26.6-12"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6.6",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:56523",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6",
    "package" : "keycloak-services"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6.6",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:56523",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6",
    "package" : "rhbk/keycloak-rhel9"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6.6",
    "release_date" : "2026-08-18T00:00:00Z",
    "advisory" : "RHSA-2026:56523",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6",
    "package" : "rhbk-openshift-rhel9/rhbk-openshift-rhel9"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-15571\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-15571" ],
  "name" : "CVE-2026-15571",
  "csaw" : false
}