---
id: CVE-2026-7507
title: >-
  A session fixation vulnerability was found in Keycloak's login-actions
  endpoints
summary: >-
  A session fixation vulnerability was found in Keycloak's login-actions
  endpoints. An unauthenticated attacker could exploit this flaw by pre-creating
  an authentication session and tricking a victim into visiting a maliciously
  crafted lin…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-290
vendor: redhat
product: build_of_keycloak
affected:
  - 'build_of_keycloak >= 26.4, < 26.4.12'
patched:
  - build_of_keycloak 26.4.12
published: '2026-05-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T15:17:29.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7507'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:19594'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:19595'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:19596'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:19597'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-7507'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2464145'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:19594'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19595'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19596'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19597'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-7507'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2464145'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7507.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-19T13:40:38.753128Z'
epss: 0.00757
epssPercentile: 0.53389
ingestedAt: '2026-09-29T16:39:33.225Z'
---

## Overview

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection or cookie ownership validation—an attacker can reset the authentication flow state. This causes Single Sign-On (SSO) to authenticate the victim transparently upon clicking the link, allowing the attacker to hijack the required-action form without needing the victim's credentials. A successful exploit could lead to complete account takeover, including highly privileged administrative accounts.

## Affected

- `build_of_keycloak >= 26.4, < 26.4.12`

## Remediation

Upgrade past the affected range:

- `build_of_keycloak 26.4.12`
