Description
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- redhat / build_of_keycloak
- redhat / build_of_keycloak26.2 – 26.2
- redhat / build_of_keycloak26.2.14 – 26.2.14
- redhat / build_of_keycloak26.4 – 26.4
- redhat / build_of_keycloak26.4.10 – 26.4.10
- redhat / keycloak
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:3925
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:3926
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:3947
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:3948
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-3047
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2441966
Updated 8m ago · 8 sources