CVE-2026-2603
EUVD-2026-1269018.03.2026, 02:16
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | build_of_keycloak | 26.2 ≤ 𝑥 < 26.2.14 |
| redhat | build_of_keycloak | 26.4 ≤ 𝑥 < 26.4.10 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.2 | 26.2.14-1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.2 | 26.2-16 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.2 | 26.2-16 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.10-1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-12 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-12 ≤ 𝑥 < * | ADP |
Common Weakness Enumeration
References