Junglewise Threat Intelligence

CVE-2026-3047: Keycloak SAML broker authentication bypass via disabled client

CVE-2026-3047 · Severity: high · CVSS 8.8 · Published 2026-03-05

Technologies: Red Hat build of Keycloak. Vendors: Maven, Red Hat.

Executive brief

A security flaw has been identified in Keycloak, a popular open-source identity and access management solution. The vulnerability allows a user to log in through a disabled SAML client if it is configured as a landing target for identity provider logins. Once logged in, an attacker could gain unauthorized access to other active applications and services within the same single sign-on (SSO) environment without needing to re-authenticate.

Technical details

A vulnerability exists in the org.keycloak.broker.saml component of Keycloak. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, the system fails to properly enforce the disabled status during the authentication flow. This allows a remote attacker with low privileges to complete the login process and establish a valid Single Sign-On (SSO) session. Consequently, the attacker can access other enabled clients within the realm without further authentication. Red Hat has released security advisories (RHSA-2026:3925, RHSA-2026:3926, RHSA-2026:3947, RHSA-2026:3948) to address this issue in Keycloak versions 26.2.14 and 26.4.10.

Affected products

  • Red Hat Red Hat build of Keycloak 26.2, 26.4

Timeline

  • 2026-03-05: disclosed
  • 2026-03-05: patched: Fixed in Red Hat build of Keycloak 26.2.14 and 26.4.10

References

Related threats