# Keycloak session hijack via prompt=login re-authentication

Source: https://startwithidentity.com/cves/cve-2023-6787/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[Keycloak](https://startwithidentity.com/vendors/open-source/keycloak/)'s re-authentication path (`prompt=login`) could attach a new login to someone else's active session. A session that looked like step-up was a [session hijack](https://startwithidentity.com/glossary/session-hijacking/). Assigned CVE-2023-6787, public with the April 2024 Keycloak/RHSA train (alongside [CVE-2023-6544](https://startwithidentity.com/cves/cve-2023-6544/) and [CVE-2023-6717](https://startwithidentity.com/cves/cve-2023-6717/)).

## Why it matters

`prompt=login` is how apps force a fresh password or MFA. If that flow can steal a session, step-up is an attack. Same class as Citrix Bleed: the session is the credential.

## What to do

- Upgrade Keycloak to the April 2024 patched line or later.
- After upgrade, invalidate sessions if the realm was public while vulnerable.
- Confirm step-up still binds to the existing `sub` and does not mint a new session for a different user.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2023-6787](https://nvd.nist.gov/vuln/detail/CVE-2023-6787)
- GitHub GHSA-c9h6-v78w-52wj / Red Hat RHSA-2024:1868
