Description
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- RedHat / build_of_keycloak26.4 – 26.4.14
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:50846
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:50847
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:50848
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:50849
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-16442
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2503138
Updated 8m ago · 8 sources