{"id":"CVE-2026-15571","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-15571","summary":"A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect…","details":"A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.","published":"2026-08-18T21:16:33.910","modified":"2026-08-18T21:16:33.910","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:56523"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:56524"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-15571"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2499591"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T21:16:33.910"}}