Executive brief
A security flaw in Keycloak, a popular identity and access management tool, allows users to log in through external providers even after an administrator has disabled them. By reusing a specific type of login request, an attacker can bypass these administrative restrictions to gain unauthorized access to protected applications. This could lead to unauthorized account access if an organization relies on disabling specific login methods to revoke access.
Technical details
An authentication bypass vulnerability exists in Keycloak's IdentityBrokerService.performLogin endpoint due to improper enforcement of disabled Identity Providers (IdP). The root cause is a failure to validate the 'enabled' status of an IdP when processing a reused, previously generated login request. An unauthenticated remote attacker who knows the target IdP alias can bypass administrative restrictions to authenticate via a provider that should be inactive. This issue affects Red Hat build of Keycloak and Red Hat Single Sign-On; fixes are available in Keycloak version 26.4.10 and associated Red Hat errata (RHSA-2026:3947).
Affected products
- Red Hat build of Keycloak 26.4.10-1
- Red Hat Single Sign-On 7 7
Timeline
- 2026-03-05: disclosed
- 2026-03-05: patched
References
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html
- https://access.redhat.com/errata/RHSA-2026:3947
- https://access.redhat.com/errata/RHSA-2026:3948
- https://access.redhat.com/security/cve/CVE-2026-3009
- https://bugzilla.redhat.com/show_bug.cgi?id=2441867