PT-2026-95069 · Oracle+2 · Mysql Server+2
CVE-2026-90997
·
Published
2026-09-16
·
Updated
2026-09-19
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak versions 26.7.0 through 26.7.3
Description
A flaw exists when the software is deployed in stateless mode using MySQL or MariaDB. A mismatch in row-count semantics between the database driver and the application logic allows the replay protection mechanism for single-use security artifacts to be bypassed. An attacker who intercepts artifacts such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes can replay them to gain unauthorized access to the login flow or the token endpoint.
Recommendations
Update to version 26.7.4 or later.
Set the JDBC parameter
useAffectedRows=true.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak
Mariadb
Mysql Server