THREAT OPS › Threat News › [NVD] CVE-2025-7365 (HIGH 7.1) — A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to mod
[NVD] CVE-2025-7365 (HIGH 7.1) — A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to mod
CVE-2025-7365 CVSS: 7.1 HIGH Published: 2025-07-10T15:15:30.427
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerability allows the attacker to modify their email address to match that of a victim's acc
Indicators of compromise
- CVE-2025-7365cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-7365