CVE-2026-37982
published 2026-05-19CVE-2026-37982: A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's…
PriorityP343medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
0.44%
35.7th percentile
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | >= 26.4 < 26.4.12 | 26.4.12 |
| rhbk | keycloak-rhel9 | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w4p5-rfh6-cwrv: A flaw was found in Keycloak
ghsa_unreviewed·2026-05-19
CVE-2026-37982 [MEDIUM] CWE-294 GHSA-w4p5-rfh6-cwrv: A flaw was found in Keycloak
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
GHSA
Keycloak: Unauthorized account takeover via WebAuthn token replay
ghsa·2026-05-19
CVE-2026-37982 [MEDIUM] CWE-294 Keycloak: Unauthorized account takeover via WebAuthn token replay
Keycloak: Unauthorized account takeover via WebAuthn token replay
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
Red Hat
keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay
vendor_redhat·2026-05-19·CVSS 6.8
CVE-2026-37982 [MEDIUM] keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay
keycloak: org.keycloak.authentication: Keycloak: Unauthorized account takeover via WebAuthn token replay
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
Statement: This vulnerability has a Moderate impact on Red Hat Build of Keycloak (RHBK). A flaw in Keycloak's WebAuthn flow allows an attacker who gains access to an execute-actions email link to replay tokens containing WEBAUTHN_REGISTER or WEBAUTHN_PASSWORDLESS_REGISTER. Thi
No detection rules found.
No public exploits indexed.
2026-05-19
Published