THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-7365 (HIGH 7.1) — A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to mod

[NVD] CVE-2025-7365 (HIGH 7.1) — A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to mod

lownvdPublished 2025-07-10

CVE-2025-7365 CVSS: 7.1 HIGH Published: 2025-07-10T15:15:30.427

A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's acc

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-7365