← All Advisories

CVE-2026-7507

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-7507

Key Details

CVECVE-2026-7507
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-06
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-290 (Authentication Bypass by Spoofing)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Build of Keycloak
Red HatRHEL-8 based Middleware Containers
Red HatRed Hat build of Keycloak 26.2
Red HatRed Hat build of Keycloak 26.4
Red HatRed Hat build of Keycloak 26.2.16
Red HatRed Hat build of Keycloak 26.4.12
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection or cookie ownership validation—an attacker can reset the authentication flow state. This causes Single Sign-On (SSO) to authenticate the victim transparently upon clicking the link, allowing the attacker to hijack the required-action form without needing the victim's credentials. A successful exploit could lead to complete account takeover, including highly privileged administrative accounts. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-7507
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-7507
Vendor advisoryhttps://access.redhat.com/errata/RHSA-2026:19594