CVE-2026-37982 Details
Description
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
A vulnerability in Keycloak's WebAuthn flow allows remote attackers to replay 'ExecuteActionsActionToken' tokens, leading to unauthorized enrollment of hardware-backed credentials and persistent account takeover. This issue arises because the 'canUseTokenRepeatedly()' function incorrectly treats certain tokens as reusable, allowing interception of execute-actions email links to register authenticators on victims' accounts. Exploitation requires WebAuthn actions to be enabled and the email link to be compromised.
To mitigate this vulnerability, consider disabling WebAuthn required actions in Keycloak if they are not essential for your deployment. Consult the Keycloak documentation for specific steps to disable WebAuthn required actions. Note that applying configuration changes may require a service restart and could impact functionality that relies on WebAuthn registration.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:19596 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:19597 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-37982 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2455329 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-294 | Authentication Bypass by Capture-replay | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | >= 26.4, < 26.4.12 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |