CVE-2025-7365: Keycloak: phishing attack via email verification step in first login flow
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-xhpr-465j-7p9q. This link is maintained to preserve external references.
Original Description A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's account, triggering a verification email sent to the victim's email address. The attacker's email address is not present in the verification email content, making it a potential phishing opportunity. If the victim clicks the verification link, the attacker can gain access to the victim's account.
Other sources
There is a flaw with the first login flow where, during a IdP login, an attacker with a registered account can initiate the process to merge accounts with an existing victim's account. The attacker will subsequently be prompted to "review profile" information, which allows the the attacker to modify their email address to that of a victim's account. This triggers a verification email sent to the victim's email address. If the victim clicks the verification link, the attacker can gain access to the victim's account. While not a zero-interaction attack, the attacker's email address is not directly present in the verification email content, making it a potential phishing opportunity.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.keycloak:keycloak-servicesto a version that resolves this vulnerability.Fixed in 26.3.0 - Upgrade
Upgrade
maven/org.keycloak:keycloak-servicesto a version that resolves this vulnerability.Fixed in 26.2.6 - Upgrade
Upgrade
maven/org.keycloak:keycloak-servicesto a version that resolves this vulnerability.Fixed in 26.0.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.0.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.2.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7365?
CVE-2025-7365 is considered a high-severity vulnerability due to its potential to allow attackers to modify sensitive profile information.
How do I fix CVE-2025-7365?
To fix CVE-2025-7365, update to Red Hat Keycloak version 26.3.0 or later.
What types of accounts are affected by CVE-2025-7365?
CVE-2025-7365 affects accounts that are involved in the account merging process during identity provider logins.
Can CVE-2025-7365 be exploited by unauthenticated users?
No, CVE-2025-7365 can only be exploited by authenticated attackers who have access to merge accounts.
What impact does CVE-2025-7365 have on user data?
CVE-2025-7365 allows attackers to alter profile information of users whose accounts can be merged, compromising data integrity.