Description
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.
Problem types
Missing Authentication for Critical Function
Product status
26.2.14-1 (rpm) before *
26.2-16 (rpm) before *
26.2-16 (rpm) before *
26.4.10-1 (rpm) before *
26.4-12 (rpm) before *
26.4-12 (rpm) before *
Timeline
| 2026-02-16: | Reported to Red Hat. |
| 2026-03-05: | Made public. |
Credits
Red Hat would like to thank Joy Gilbert and Reynaldo Immanuel for reporting this issue.
References
bugzilla.redhat.com/show_bug.cgi?id=2440300
access.redhat.com/errata/RHSA-2026:3925 (RHSA-2026:3925)
access.redhat.com/errata/RHSA-2026:3926 (RHSA-2026:3926)
access.redhat.com/errata/RHSA-2026:3947 (RHSA-2026:3947)
access.redhat.com/errata/RHSA-2026:3948 (RHSA-2026:3948)
access.redhat.com/security/cve/CVE-2026-2603
bugzilla.redhat.com/show_bug.cgi?id=2440300 (RHBZ#2440300)