Executive brief
A security flaw has been identified in Keycloak, a popular open-source identity and access management solution. The vulnerability allows a user to log in through a disabled SAML client if it is configured as a landing target for identity provider logins. Once logged in, an attacker could gain unauthorized access to other active applications and services within the same single sign-on (SSO) environment without needing to re-authenticate.
Technical details
A vulnerability exists in the org.keycloak.broker.saml component of Keycloak. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, the system fails to properly enforce the disabled status during the authentication flow. This allows a remote attacker with low privileges to complete the login process and establish a valid Single Sign-On (SSO) session. Consequently, the attacker can access other enabled clients within the realm without further authentication. Red Hat has released security advisories (RHSA-2026:3925, RHSA-2026:3926, RHSA-2026:3947, RHSA-2026:3948) to address this issue in Keycloak versions 26.2.14 and 26.4.10.
Affected products
- Red Hat Red Hat build of Keycloak 26.2, 26.4
Timeline
- 2026-03-05: disclosed
- 2026-03-05: patched: Fixed in Red Hat build of Keycloak 26.2.14 and 26.4.10
References
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2026:3925
- https://access.redhat.com/errata/RHSA-2026:3926
- https://access.redhat.com/errata/RHSA-2026:3947
- https://access.redhat.com/errata/RHSA-2026:3948
- https://access.redhat.com/security/cve/CVE-2026-3047