Redpacketsecurity Keycloak Vulnerability CVE-2026-90997 Allows Replay Attacks
Article Content
- •CVE-2026-90997 allows replay attacks in Keycloak with MySQL/MariaDB.
- •Attackers can intercept single-use security artifacts for unauthorized access.
- •Mitigation requires JDBC configuration changes and service restarts.
A high-impact vulnerability (CVE-2026-90997) was identified in Keycloak when deployed in stateless mode with MySQL or MariaDB. The flaw arises from a mismatch in row-count semantics between the database driver and Keycloak's logic, enabling attackers to bypass replay protection. This allows interception and replay of single-use security artifacts like JWT assertions and TOTP codes, leading to unauthorized access to token endpoints or login flows. Organizations using these configurations are at risk, particularly those with internet-facing identity services. Mitigation involves configuring the JDBC connection string and restarting the Keycloak service. The vulnerability was published on September 17, 2026, and is classified as high severity due to the potential for account takeover and service impersonation. Active exploitation status is unknown, and organizations are urged to apply the recommended fixes promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-90997 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…