Skip to content
Red HatCVE-2026-15571

A flaw was found in the legacy client-initiated account-linking endpoint of...

High7.3CVE-2026-15571 · Published Aug 18, 2026 · updated Aug 20, 2026

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Data Grid 8
Product
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform Expansion Pack
Product
all versionsNo fix yet
Red Hat Single Sign-On 7
Product
all versionsNo fix yet
Red Hat build of Keycloak 26.6.6
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Advanced Cluster Management for Kubernetes 2: secrets in logs
Medium6.5Aug 18
Red Hat Multicluster Engine for Kubernetes: information disclosure
High8.7Aug 18
Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure
Medium5.4Aug 18
Red Hat Advanced Cluster Management: improper privilege management
Medium5.8Aug 18
Red Hat Advanced Cluster Management for Kubernetes 2: code execution
Medium4.4Aug 18
reset-credentials flow of the keycloak-services: weak password recovery
Critical9.1Aug 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.