Keycloak — predictable account-linking hash enables account takeover via a malicious OIDC client. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); Red Hat records a public date of 2026-08-18. A second account-takeover path on the same identity surface as CVE-2026-18963 and one reason the 26.6.6 upgrade is not equivalent to 26.4.15.
cve · CVE-2026-15571
Coverage timeline
0
first 2026-08-19 → last 2026-08-19
no data
Peak priority
—
no matching entries
Sources cited
0
0 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet
Story timeline
No published entries reference this entity yet.
Entries about Keycloak — predictable account-linking hash enables account takeover via a malicious OIDC client. Closed by RHSA-2026:56523 (Red Hat build of Keycloak 26.6.6, 2026-08-18); Red Hat records a public date of 2026-08-18. A second account-takeover path on the same identity surface as CVE-2026-18963 and one reason the 26.6.6 upgrade is not equivalent to 26.4.15.
No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.