๐Ÿ” CVE Alert

CVE-2026-90997

HIGH 7.4

Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes, to replay them. Successful exploitation grants unauthorized access to the token endpoint or login flow.

CWE CWE-294
Vendor keycloak
Product keycloak
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for keycloak keycloak

Be the first to know when new high vulnerabilities affecting keycloak keycloak are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Keycloak / Keycloak
26.7.0 < 26.7.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/cve-2026-90997 github.com: https://github.com/keycloak/keycloak