
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4325 is a vulnerability in Keycloak titled "Replay of action tokens via improper handling of single-use entries." The flaw exists in Keycloak's SingleUseObjectProvider, a global key-value store that lacks proper type and namespace isolation, allowing attackers to delete arbitrary single-use entries and replay consumed action tokens such as password reset links. Affected products include Red Hat Build of Keycloak versions 26.2, 26.2.15, 26.4, and 26.4.11, as well as upstream org.keycloak:keycloak-services versions prior to 26.5.7. The vulnerability was reported on March 17, 2026, and publicly disclosed on April 2, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium/Moderate) (Red Hat CVE, GitHub Advisory).
The root cause is classified as CWE-653 (Improper Isolation or Compartmentalization): Keycloak's SingleUseObjectProvider operates as a flat, global key-value store without enforcing type or namespace boundaries between different categories of single-use tokens. Because entries from different token types share the same namespace, an attacker can craft requests that delete entries belonging to other token types — specifically consumed action tokens like password reset links — effectively "un-consuming" them and making them replayable. Exploitation requires network access and user interaction (e.g., a victim must have previously triggered an action token flow), but no authentication privileges are needed. The related GitHub commit and issue are publicly referenced (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows an attacker to replay previously consumed action tokens — most critically, password reset links — potentially enabling unauthorized account takeover or access to victim accounts. The integrity impact is rated High, as an attacker can manipulate authentication flows and bypass one-time-use token controls. There is no direct confidentiality or availability impact, but account compromise could serve as a foothold for further lateral movement within systems protected by the affected Keycloak instance (GitHub Advisory, Red Hat CVE).
Red Hat has released patches addressing this vulnerability across multiple errata advisories issued on April 2, 2026. Affected users should upgrade to the following fixed versions:
org.keycloak:keycloak-services to version 26.5.7 or laterAs interim measures, administrators should review authentication logs for suspicious token replay activity, validate any password reset or action token transactions that occurred during the vulnerability window, and consider implementing additional monitoring around the SingleUseObjectProvider component (RHSA-2026:6475, RHSA-2026:6476, GitHub Advisory).
Red Hat classified the advisory as "Important" severity and released coordinated errata across standalone and OpenShift container deployments on the same day as disclosure (RHSA-2026:6475). The vulnerability was noted alongside several other Keycloak flaws in the same advisory batch, including CVE-2026-4282 (a related SingleUseObjectProvider isolation flaw enabling privilege escalation), suggesting a broader audit of the component. No significant independent researcher commentary or notable social media discussion has been identified beyond automated CVE tracking posts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."