2026-05-21NOTABLEKeycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience
Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2)
cve · CVE-2026-6856
Coverage
1
first 2026-05-21 → last 2026-05-21
Latest activity
2026-05-21
Keycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, healthcare, education · regions: europe, dach
Sources cited
6
6 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-6856, newest first. Check the date before acting on an older one.
- Upgrade Keycloak to 26.6.2 with priority on identity-federation deployments (national digital-identity platforms, eHealth federations). The OIDC session-fixation (CVE-2026-7507), WebAuthn execute-actions replay (CVE-2026-37982) and cross-realm IDOR in Authorization Services (CVE-2026-4630) are the operationally-most-dangerous CVEs in the batch (. For Red Hat build of Keycloak, apply the corresponding RHSA advisories on the 26.2.x branch.2026-05-21CVE-2026-7507 +5
Defender insights
What each entry about CVE-2026-6856 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (3 across 6 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts
- PersistenceValid Accounts · Account Manipulation: Device Registration · Modify Authentication Process
- Privilege EscalationValid Accounts · Account Manipulation: Device Registration
- StealthValid Accounts
- Defense ImpairmentModify Authentication Process
- Credential AccessModify Authentication Process
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
Defense Impairment TA0112
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
Credential Access TA0006
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-21/keycloak-26-6-2-16-cves-including-oidc-session-fixation-cve · ATT&CK page ↗
Entries about Keycloak WebAuthn packed self-attestation acceptable-AAGUID policy bypass enabling enrolment of hardware tokens outside policy (Keycloak 26.6.2) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Akira×1
- Keycloak admin evaluate-scopes endpoint cross-role PII leakage bypassing user-view permissions (Keycloak 26.6.2)×1
- Keycloak Authorization Services Protection API cross-realm IDOR allowing realm-A authenticated attacker to access realm-B resources (Keycloak 26.6.2)×1
- Keycloak execute-actions token replay enabling unauthorised WebAuthn / FIDO2 credential enrollment on victim account (Keycloak 26.6.2)×1
- Keycloak OIDC login flow session fixation enabling account takeover (Keycloak 26.6.2; BSI WID-SEC-2026-1612 HIGH)×1
- Keycloak OIDC token introspection endpoint does not enforce audience restriction; lightweight access tokens leak claims cross-client (Keycloak 26.6.2)×1
Where this entity is cited
Source distribution
- cybersecuritydive.com1 (17%)
- drupal.org1 (17%)
- hadrian.io1 (17%)
- keycloak.org1 (17%)
- msrc.microsoft.com1 (17%)
- wid.cert-bund.de1 (17%)
External references
All cited sources (6)
- keycloak.orgprimaryKeycloak Projecthttps://www.keycloak.org/2026/05/keycloak-2662-released
- cybersecuritydive.comCybersecurity Divehttps://www.cybersecuritydive.com/news/patch-bypass-hackers-exploit-flaw-sonicwall/820600/
- drupal.orgDrupalhttps://www.drupal.org/sa-core-2026-004
- hadrian.ioHadrianhttps://hadrian.io/blog/cve-2026-45829----chromadb-python-server-hands-you-rce-before-it-asks-who-you-are
- msrc.microsoft.comMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42822
- wid.cert-bund.deBSI CERT-Bund WID-SEC-2026-1612https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1612