Skip to content

[GHSA-8g9r-9wjw-37j4] Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API#7236

Merged
advisory-database[bot] merged 1 commit intomainfrom
Ankush-Pathak-GHSA-8g9r-9wjw-37j4
Mar 26, 2026
Merged

[GHSA-8g9r-9wjw-37j4] Keycloak: Improper Access Control Leading to MFA Deletion and Account Takeover in Keycloak Account REST API#7236
advisory-database[bot] merged 1 commit intomainfrom
Ankush-Pathak-GHSA-8g9r-9wjw-37j4

Conversation

@Ankush-Pathak
Copy link
Contributor

Updates

  • Affected products

Comments
<=26.5.5 implies 26.5.6 is not vulnerable which is not the case. Keycloak is currently in the process of backporting the fix(keycloak/keycloak#47413) to 26.5, and the patch is likely to be included in the next release (~26.5.7)

@advisory-database advisory-database bot merged commit 8d529de into main Mar 26, 2026
3 checks passed
@advisory-database
Copy link
Contributor

Hi @Ankush-Pathak! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the Ankush-Pathak-GHSA-8g9r-9wjw-37j4 branch March 26, 2026 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant