PT-2026-95069 · Oracle+2 · Mysql Server+2

CVE-2026-90997

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak versions 26.7.0 through 26.7.3
Description A flaw exists when the software is deployed in stateless mode using MySQL or MariaDB. A mismatch in row-count semantics between the database driver and the application logic allows the replay protection mechanism for single-use security artifacts to be bypassed. An attacker who intercepts artifacts such as JWT client assertions, DPoP proofs, or one-time password (TOTP) codes can replay them to gain unauthorized access to the login flow or the token endpoint.
Recommendations Update to version 26.7.4 or later. Set the JDBC parameter useAffectedRows=true.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90997

Affected Products

Keycloak
Mariadb
Mysql Server