A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes, to replay them. Successful exploitation grants unauthorized access to the token endpoint or login flow.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title keycloak-services: Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch
References

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes, to replay them. Successful exploitation grants unauthorized access to the token endpoint or login flow.
Title keycloak-services: Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch
Weaknesses CWE-294
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Important


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-17T18:56:17.887Z

Reserved: 2026-09-14T14:53:37.815Z

Link: CVE-2026-90997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T19:17:06.740

Modified: 2026-09-17T19:17:06.740

Link: CVE-2026-90997

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:21:23Z

Links: CVE-2026-90997 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses