9.1
CVE-2026-16443
- EPSS 0.15%
- Veröffentlicht 05.08.2026 13:44:09
- Zuletzt bearbeitet 10.08.2026 18:52:14
- CVE-Watchlists
- Unerledigt
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Mögliche Gegenmaßnahme
Keycloak Server: Install latest version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Build Of Keycloak Version >= 26.4 < 26.4.14
Redhat ≫ Build Of Keycloak Version >= 26.6 < 26.6.5
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemKeycloak
≫
Produkt
Keycloak Server
Version
< 26.4.14
Version
< 26.6.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.051 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| RedHat | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
https://access.redhat.com/security/cve/CVE-2026-16443
https://bugzilla.redhat.com/show_bug.cgi?id=2503139
https://access.redhat.com/errata/RHSA-2026:50846
https://access.redhat.com/errata/RHSA-2026:50847
https://access.redhat.com/errata/RHSA-2026:50848
https://access.redhat.com/errata/RHSA-2026:50849
https://github.com/keycloak/keycloak/security/advisories/GHSA-f8m4-v488-rmrm