Description
A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Account lockout (Denial of Service) via external username collision
Action: Patch Now
AI Analysis

Impact

A flaw in the first‑broker‑login flow of Keycloak’s keycloak‑services component permits an attacker to register a matching username on an external identity provider. When the broker attempts to link this account, it triggers a collision that locks the legitimate user out, resulting in denial of service and potential loss of access for that user. The weakness is an authentication bypass, categorized as CWE‑287.

Affected Systems

Red Hat Single Sign‑On 7 and Red Hat builds of Keycloak versions 26.4, 26.4.16, 26.6, and 26.6.7 are affected. The flaw exists in the keycloak‑services component that handles broker‑initiated logins.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate severity. The EPSS score of less than 1 % means the likelihood of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires the ability to control or create a user on an external provider and to initiate a broker login; no additional privileged conditions are listed. If an attacker can influence external user registration, they can cause account lockout by username collision.

Generated by OpenCVE AI on September 18, 2026 at 00:13 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the relevant Red Hat errata (RHSA‑2026:68276‑68280) that corrects the broker‑originated username collision flaw.
  • Ensure that the running version of Keycloak or Red Hat Single Sign‑On is at least the patched 26.6.7 or 26.4.16 version.
  • Restrict or disable broker‑initiated user creation to prevent external providers from registering usernames that would collide with internal accounts.

Generated by OpenCVE AI on September 18, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Vendors & Products Redhat build Of Keycloak

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat red Hat Single Sign On

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.
Title Keycloak-services: keycloak-services: broker-originated username collision causes account lockout
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-287
CPEs cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-16T18:35:08.909Z

Reserved: 2026-08-12T08:42:14.784Z

Link: CVE-2026-19607

cve-icon Vulnrichment

Updated: 2026-09-16T18:25:15.167Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T16:17:06.607

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-19607

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T13:01:00Z

Links: CVE-2026-19607 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:44Z

Weaknesses