Status: UPDATED
| Advisory ID: CVE-2026-7507
Key Details
| CVE | CVE-2026-7507 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-10-06 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-290 (Authentication Bypass by Spoofing) |
Affected Products, Subsystems & Sectors
| Subsystems | OT Supporting Infrastructure |
| Sectors | Multiple |
What to Know
A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection or cookie ownership validation—an attacker can reset the authentication flow state. This causes Single Sign-On (SSO) to authenticate the victim transparently upon clicking the link, allowing the attacker to hijack the required-action form without needing the victim's credentials. A successful exploit could lead to complete account takeover, including highly privileged administrative accounts. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.
References