CVE-2026-37982: Red Hat Build Of Keycloak

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.

Affected products

  • Red Hat Build Of Keycloak: from 26.4, before 26.4.12 (fixed in 26.4.12)

Published 2026-05-19. Last modified 2026-06-17.