CVE-2026-19607: Red Hat Build Of Keycloak 26.4

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register a matching username on an external provider to trigger a collision in Keycloak, which results in the legitimate user being locked out of their account.

Affected products

  • Red Hat Red Hat Build Of Keycloak 26.4: before 26.4.16-2 (fixed in 26.4.16-2); before 26.4-26 (fixed in 26.4-26)
  • Red Hat Red Hat Build Of Keycloak 26.4.16
  • Red Hat Red Hat Build Of Keycloak 26.6: before 26.6.7-3 (fixed in 26.6.7-3); before 26.6-20 (fixed in 26.6-20)
  • Red Hat Red Hat Build Of Keycloak 26.6.7
  • Red Hat Red Hat Single Sign-On 7

Published 2026-09-16. Last modified 2026-09-16.