CVE-2025-7365: Keycloak: phishing attack via email verification step in first login flow

Published Jul 8, 2025
·
Updated

Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-xhpr-465j-7p9q. This link is maintained to preserve external references.

Original Description A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's account, triggering a verification email sent to the victim's email address. The attacker's email address is not present in the verification email content, making it a potential phishing opportunity. If the victim clicks the verification link, the attacker can gain access to the victim's account.

Other sources

There is a flaw with the first login flow where, during a IdP login, an attacker with a registered account can initiate the process to merge accounts with an existing victim's account. The attacker will subsequently be prompted to "review profile" information, which allows the the attacker to modify their email address to that of a victim's account. This triggers a verification email sent to the victim's email address. If the victim clicks the verification link, the attacker can gain access to the victim's account. While not a zero-interaction attack, the attacker's email address is not directly present in the verification email content, making it a potential phishing opportunity.

Red Hat

Affected Software

6 affected componentsFixes available
Red Hat Keycloak
maven/org.keycloak:keycloak-services<26.3.0
26.3.0
maven/org.keycloak:keycloak-services>=26.2.0<26.2.6
26.2.6
maven/org.keycloak:keycloak-services<26.0.13
26.0.13
redhat keycloak
IBM Concert Software<=1.0.0-2.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.keycloak:keycloak-services to a version that resolves this vulnerability.

    Fixed in 26.3.0
  2. Upgrade

    Upgrade maven/org.keycloak:keycloak-services to a version that resolves this vulnerability.

    Fixed in 26.2.6
  3. Upgrade

    Upgrade maven/org.keycloak:keycloak-services to a version that resolves this vulnerability.

    Fixed in 26.0.13
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 26.0.13
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 26.2.6
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 26.3.0

Event History

Jul 8, 2025
Data Sourced
via Red Hat·08:32 PM
DescriptionSeverityAffected Software
Jul 10, 2025
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Data Sourced
via GitHub·03:31 PM
DescriptionSeverityWeaknessAffected Software
Jul 30, 2025
Withdrawn
via GitHub·01:15 PM
Updated
via GitHub·01:16 PM
DescriptionAffected Software
Jan 14, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-7365?

CVE-2025-7365 is considered a high-severity vulnerability due to its potential to allow attackers to modify sensitive profile information.

2

How do I fix CVE-2025-7365?

To fix CVE-2025-7365, update to Red Hat Keycloak version 26.3.0 or later.

3

What types of accounts are affected by CVE-2025-7365?

CVE-2025-7365 affects accounts that are involved in the account merging process during identity provider logins.

4

Can CVE-2025-7365 be exploited by unauthenticated users?

No, CVE-2025-7365 can only be exploited by authenticated attackers who have access to merge accounts.

5

What impact does CVE-2025-7365 have on user data?

CVE-2025-7365 allows attackers to alter profile information of users whose accounts can be merged, compromising data integrity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203