๐Ÿ” CVE Alert

CVE-2026-19607

MEDIUM 5.3

Keycloak-services: keycloak-services: broker-originated username collision causes account lockout

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.

CWE CWE-287
Vendor red hat
Product red hat build of keycloak 26.4
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of keycloak 26.4

Be the first to know when new medium vulnerabilities affecting red hat red hat build of keycloak 26.4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4
All versions affected
Red Hat / Red Hat build of Keycloak 26.4.16
All versions affected
Red Hat / Red Hat build of Keycloak 26.4.16
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6
All versions affected
Red Hat / Red Hat build of Keycloak 26.6.7
All versions affected
Red Hat / Red Hat build of Keycloak 26.6.7
All versions affected
Red Hat / Red Hat Single Sign-On 7
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:68276 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:68277 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:68278 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:68280 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-19607 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2514529

Credits

Red Hat would like to thank Anurag Mondal (NetSPI) for reporting this issue.