← Back to search

CVE-2026-94218

3.1 LOW

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows users to bypass mandatory two-factor authentication by manually visiting a session restart link, gaining unauthorized access.
Exploitability
Exploitation requires user interaction and knowledge of the session restart link; moderately difficult.
Blast radius
If exploited, it could lead to unauthorized access for affected users, compromising account security.
Prioritized remediation
Disable manual session restart links or enforce strict access controls around them.
auth-bypasswebidentity-management

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authentication (2FA) setup, through a client policy. A user can bypass this requirement by manually visiting a specific session restart web link during the login process. This action clears the internal markers that track the required security steps, allowing the user to log in with only a password and gain access without completing the mandated 2FA setup.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-862

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.