Description
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by manually visiting a specific session restart web link during the login process. This action clears the internal markers that track the required security steps, allowing the user to log in with only a password and gain access without completing the mandated 2FA setup.
Published: 2026-09-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Two‑Factor Authentication Bypass
Action: Assess Impact
AI Analysis

Impact

A flaw in Keycloak’s session management lets a user bypass a mandatory two‑factor authentication requirement that is enforced through a client policy. By manually visiting a specific session‑restart web link during the login sequence, the system clears the internal markers that track pending authentication steps, allowing the user to authenticate with only a password. The weakness identified is an Authentication Process flaw (CWE‑862) and the impact is the loss of the confidentiality guarantee that 2FA protects.

Affected Systems

The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific patch versions are listed, so any installation of these products that implements client policies requiring two‑factor authentication is potentially vulnerable.

Risk and Exploitability

The CVSS score of 3.1 indicates low technical severity, but the business impact of allowing users to circumvent additional authentication steps can be substantial, especially in compliance‑driven environments. EPSS data are unavailable and the issue is not listed in the CISA KEV catalog. The attack requires only manual access to a known web link during login, which means a credentialed or non‑credentialed user can exploit it if the session‑restart endpoint is reachable. Based on the description, the likely attack vector is a simple, client‑side action that can be performed by anyone who can trigger the login flow.

Generated by OpenCVE AI on September 21, 2026 at 08:40 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Check for a vendor‑issued patch that corrects the session‑restart handling and apply it as soon as it becomes available.
  • If a patch is not yet released, limit exposure by disabling or blocking the session‑restart endpoint with network or application firewall rules.
  • Adjust client policy configuration to enforce 2FA without relying on the session‑restart endpoint, and validate enforcement through functional testing.
  • Monitor authentication logs for unexpected use of the session‑restart link and alert on repeated attempts to restart sessions during login.

Generated by OpenCVE AI on September 21, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Mon, 21 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by manually visiting a specific session restart web link during the login process. This action clears the internal markers that track the required security steps, allowing the user to log in with only a password and gain access without completing the mandated 2FA setup.
Title Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpoint
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T10:28:28.447Z

Reserved: 2026-09-21T06:00:52.805Z

Link: CVE-2026-94218

cve-icon Vulnrichment

Updated: 2026-09-21T10:28:18.588Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-21T07:16:54.560

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-94218

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-19T20:22:03Z

Links: CVE-2026-94218 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T08:45:12Z

Weaknesses