Executive brief
Keycloak, an open-source identity and access management solution, contains a flaw in how it handles certain authentication requests. An unauthorized attacker can send specially crafted messages to the system and observe the resulting error messages to learn internal details about how different clients are configured. While this does not directly grant access to accounts, it provides information that could be used to plan more targeted attacks against the organization's authentication infrastructure.
Technical details
A Generation of Error Message Containing Sensitive Information (CWE-209) vulnerability exists in the Keycloak SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint. A remote, unauthenticated attacker can exploit this by sending specially crafted SOAP requests with varying client IDs. By analyzing the distinct 'faultstrings' returned in the SOAP responses, the attacker can perform reconnaissance to determine the protocol type of specific clients. This information disclosure is patched in Keycloak version 26.6.3.
Affected products
- Keycloak keycloak-services <= 26.4.7, >= 26.5.0, < 26.6.3
- Red Hat Red Hat build of Keycloak 26.4, 26.6
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory
- 2026-06-10: patched: Red Hat release 26.6.3 issued