VDB
Sign up
MEDIUM6.8

GHSA-w4p5-rfh6-cwrv

Keycloak: Unauthorized account takeover via WebAuthn token replay

Quick fix

GHSA-w4p5-rfh6-cwrv — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.6.2</version> for org.keycloak:keycloak-services

Details

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 26.6.2
Fix# pom.xml: bump <version>26.6.2</version> for org.keycloak:keycloak-services

References