{"id":"CVE-2026-94218","published":"2026-09-21T07:16:54.560","lastModified":"2026-09-21T11:17:13.957","description":"A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by manually visiting a specific session restart web link during the login process. This action clears the internal markers that track the required security steps, allowing the user to log in with only a password and gain access without completing the mandated 2FA setup.","cvssScore":3.1,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-94218","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2537314","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows users to bypass mandatory two-factor authentication by manually visiting a session restart link, gaining unauthorized access.","exploitability":"Exploitation requires user interaction and knowledge of the session restart link; moderately difficult.","blast_radius":"If exploited, it could lead to unauthorized access for affected users, compromising account security.","remediation":"Disable manual session restart links or enforce strict access controls around them.","tags":["auth-bypass","web","identity-management"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:37:38.691Z"}}