A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's account, triggering a verification email sent to the victim's email address. The attacker's email address is not present in the verification email content, making it a potential phishing opportunity. If the victim clicks the verification link, the attacker can gain access to the victim's account.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00015}

epss

{'score': 0.00016}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00015}


Thu, 10 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Jul 2025 14:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's account, triggering a verification email sent to the victim's email address. The attacker's email address is not present in the verification email content, making it a potential phishing opportunity. If the victim clicks the verification link, the attacker can gain access to the victim's account.
Title keycloak: Phishing attack via email verification step in first login flow Keycloak: phishing attack via email verification step in first login flow
First Time appeared Redhat
Redhat build Keycloak
CPEs cpe:/a:redhat:build_keycloak:
Vendors & Products Redhat
Redhat build Keycloak
References

Wed, 09 Jul 2025 00:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title keycloak: Phishing attack via email verification step in first login flow
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-07-10T14:20:45.775Z

Updated: 2025-07-10T20:16:34.172Z

Reserved: 2025-07-08T18:22:15.734Z

Link: CVE-2025-7365

cve-icon Vulnrichment

Updated: 2025-07-10T20:16:31.003Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-10T15:15:30.427

Modified: 2025-07-15T13:24:41.097

Link: CVE-2025-7365

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-06-20T00:00:00Z

Links: CVE-2025-7365 - Bugzilla