CVE-2026-94218
3.1 LOWPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows users to bypass mandatory two-factor authentication by manually visiting a session restart link, gaining unauthorized access.
- Exploitability
- Exploitation requires user interaction and knowledge of the session restart link; moderately difficult.
- Blast radius
- If exploited, it could lead to unauthorized access for affected users, compromising account security.
- Prioritized remediation
- Disable manual session restart links or enforce strict access controls around them.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by manually visiting a specific session restart web link during the login process. This action clears the internal markers that track the required security steps, allowing the user to log in with only a password and gain access without completing the mandated 2FA setup.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-862
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-15958
- HIGHCVE-2026-16561
- HIGHCVE-2026-16605
- HIGHCVE-2026-17070
- CRITICALCVE-2026-4431
- MEDIUMCVE-2026-48974PoC
- HIGHCVE-2026-54418PoC
- HIGHCVE-2026-6079
Related by shared AI tags and CWE weakness class. Browse the full archive.