PatchSiren cyber security CVE debrief
CVE-2026-18209 Red Hat CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:27.467Z and has not been modified since then. The flaw in the keycloak-services component of Keycloak allows attackers to inject duplicate security parameters into the login response by exploiting the security check's limitation to only inspect the query portion of a redirect URL and ignore the fragment portion. This issue can lead to session fixation or account confusion if a client application is not configured correctly. Administrators of Keycloak instances and developers of client applications using Keycloak for OIDC authentication should review their configurations and implementations to prevent session fixation or account confusion attacks.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- LOW 3.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-08-07
Who should care
Administrators of Keycloak instances and developers of client applications using Keycloak for OIDC authentication should review their configurations and implementations to prevent session fixation or account confusion attacks. They should also verify Keycloak configurations for wildcard redirect URIs and ensure client applications handle security parameters correctly.
Technical summary
A flaw in the keycloak-services component of Keycloak allows attackers to inject duplicate security parameters into the login response by exploiting the security check's limitation to only inspect the query portion of a redirect URL and ignore the fragment portion. This issue can lead to session fixation or account confusion if a client application is not configured correctly. The vulnerability affects Keycloak instances with wildcard redirect URIs and client applications that do not handle security parameters correctly. Reviewing Keycloak configurations and client applications for proper setup can help prevent session fixation or account confusion attacks.
Defensive priority
Review Keycloak configurations and client applications for proper setup to prevent session fixation or account confusion attacks.
Recommended defensive actions
- Review Keycloak configurations for wildcard redirect URIs
- Verify client applications for correct security parameter handling
- Monitor for suspicious login responses
- Confirm whether affected Keycloak instances exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
Evidence is limited; verify Keycloak configurations and client applications for proper setup. The CVE record was published on 2026-07-31T08:16:27.467Z and has not been modified since then. However, defenders should review Keycloak configurations for wildcard redirect URIs, verify client applications for correct security parameter handling, and monitor for suspicious login responses.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18209 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18209
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18209 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18209
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-18209
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.