Skip to content
Keycloak Vulnerability CVE-2026-90997 Allows Replay Attacks

Keycloak Vulnerability CVE-2026-90997 Allows Replay Attacks

First seen 18 Sep 2026, 01:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 02:00 UTC
  • CVE-2026-90997 allows replay attacks in Keycloak with MySQL/MariaDB.
  • Attackers can intercept single-use security artifacts for unauthorized access.
  • Mitigation requires JDBC configuration changes and service restarts.

A high-impact vulnerability (CVE-2026-90997) was identified in Keycloak when deployed in stateless mode with MySQL or MariaDB. The flaw arises from a mismatch in row-count semantics between the database driver and Keycloak's logic, enabling attackers to bypass replay protection. This allows interception and replay of single-use security artifacts like JWT assertions and TOTP codes, leading to unauthorized access to token endpoints or login flows. Organizations using these configurations are at risk, particularly those with internet-facing identity services. Mitigation involves configuring the JDBC connection string and restarting the Keycloak service. The vulnerability was published on September 17, 2026, and is classified as high severity due to the potential for account takeover and service impersonation. Active exploitation status is unknown, and organizations are urged to apply the recommended fixes promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-17
CVE-2026-90997 published
A vulnerability in Keycloak was disclosed, affecting stateless deployments with MySQL or MariaDB.
access.redhat.com
2026-09-18
Vulnerability reported by multiple outlets
Both Red Hat and Redpacket Security reported on the Keycloak vulnerability, emphasizing its high impact.
RedpacketSecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-90997 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed