CVE-2026-2092

7.7

Red Hat · Red Hat build of Keycloak

A flaw in Keycloak's SAML broker endpoint allows unauthorized access via improperly validated encrypted assertions when the SAML response is not signed.

Executive summary

A vulnerability in the Keycloak SAML broker endpoint allows authenticated attackers to perform unauthorized access and information disclosure by injecting malicious SAML assertions.

Vulnerability

This flaw involves improper validation of input (CWE-1287) within the SAML broker endpoint. An attacker with low privileges can bypass signature requirements to inject encrypted assertions for arbitrary principals.

Business impact

The ability to manipulate SAML assertions poses a significant risk to identity and access management security. Successful exploitation allows an attacker to impersonate arbitrary users, leading to unauthorized access to protected resources and potential sensitive information disclosure. With a CVSS score of 7.7, this is a high severity issue that requires immediate attention to maintain the integrity of authentication workflows.

Remediation

Immediate Action: Update to the patched versions provided by Red Hat, specifically version 26.2.14-1 or 26.2-16 for the 26.2 branch, and 26.4.10-1 or 26.4-12 for the 26.4 branch.

Proactive Monitoring: Audit SAML authentication logs for unusual or unexpected assertion patterns and monitor for unsuccessful login attempts or unauthorized profile changes.

Compensating Controls: Ensure that strict SAML signature validation is enforced at the identity provider level and utilize network segmentation to restrict access to the SAML broker endpoint where possible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for unauthorized access and identity impersonation, organizations should prioritize patching their Red Hat build of Keycloak instances. Administrators must verify their current version against the fixed releases provided in the Red Hat errata to ensure full protection against this assertion injection vulnerability.

More Red Hat CVEs

Sources

Originally found and disclosed by Red Hat would like to thank Oleh Konko for reporting this issue., per the CVE Program record.