9.8

CVE-2026-16442

Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction

Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Mögliche Gegenmaßnahme
Keycloak Server: Install latest version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatBuild Of Keycloak Version >= 26.4 < 26.4.14
RedhatBuild Of Keycloak Version >= 26.6 < 26.6.5
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemKeycloak
Produkt Keycloak Server
Version < 26.4.14
Version < 26.6.5
Version < 26.7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.103
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
RedHat 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://access.redhat.com/security/cve/CVE-2026-16442
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2503138
Vendor Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:50846
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:50847
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:50848
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:50849
Vendor Advisory
https://github.com/keycloak/keycloak/security/advisories/GHSA-fgq2-hxm5-8xg2
Third Party Advisory