Impact
A flaw in the first‑broker‑login flow of Keycloak’s keycloak‑services component permits an attacker to register a matching username on an external identity provider. When the broker attempts to link this account, it triggers a collision that locks the legitimate user out, resulting in denial of service and potential loss of access for that user. The weakness is an authentication bypass, categorized as CWE‑287.
Affected Systems
Red Hat Single Sign‑On 7 and Red Hat builds of Keycloak versions 26.4, 26.4.16, 26.6, and 26.6.7 are affected. The flaw exists in the keycloak‑services component that handles broker‑initiated logins.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. The EPSS score of less than 1 % means the likelihood of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires the ability to control or create a user on an external provider and to initiate a broker login; no additional privileged conditions are listed. If an attacker can influence external user registration, they can cause account lockout by username collision.
OpenCVE Enrichment