# Keycloak First Broker Login TOCTOU, account-merge takeover

Source: https://startwithidentity.com/cves/cve-2025-7365/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[Keycloak](https://startwithidentity.com/vendors/open-source/keycloak/) First Broker Login checked an email (or linking condition) and then performed the account merge later. In the gap, an attacker could complete a broker login that attached their IdP identity to the victim. CWE-367. CVSS 3.1, because exploitation needs a user in the linking flow. Red Hat patched.

## Why it matters

Account merge is how "I signed in with Google" becomes "I own the corporate user." A low CVSS does not mean a low identity impact. Anyone who enables First Broker Login or email-as-identity linking needs to read this next to [Vault EntityID reuse](https://startwithidentity.com/cves/cve-2025-6013/).

## What to do

- Upgrade Keycloak. Disable First Broker Login if you do not need social or partner linking.
- Do not auto-link on email match. Require a confirmed session on the existing account first.
- Review linked-identity tables for unexpected IdP aliases.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-7365](https://nvd.nist.gov/vuln/detail/CVE-2025-7365)
- Red Hat Keycloak advisory
