CVE-2026-2603
8.1Red Hat · Red Hat build of Keycloak
A flaw in Keycloak allows remote, authenticated attackers to bypass security controls by sending valid SAML responses to the SAML endpoint for IdP-initiated broker logins.
Executive summary
A vulnerability in the Red Hat build of Keycloak allows authenticated attackers to bypass security controls and perform unauthorized logins, posing a significant risk to identity management systems.
Vulnerability
This is a case of missing authentication for a critical function (CWE-306). A remote attacker with existing low-level user privileges can exploit this flaw to bypass authentication checks for IdP-initiated broker logins, even when the specific Identity Provider is disabled.
Business impact
The ability to perform unauthorized authentication against an identity provider can lead to full account takeover or unauthorized access to protected applications. Given the CVSS score of 8.1, this represents a high-severity risk that could lead to widespread data compromise or lateral movement within the enterprise environment.
Remediation
Immediate Action: Update the Red Hat build of Keycloak to the versions specified in the vendor errata (RHSA-2026:3925, RHSA-2026:3926, RHSA-2026:3947, or RHSA-2026:3948) depending on your current deployment branch.
Proactive Monitoring: Monitor authentication logs for suspicious IdP-initiated login patterns, particularly those originating from disabled or unexpected SAML Identity Providers.
Compensating Controls: Ensure that strict network-level access controls are in place for the SAML endpoint and consider implementing additional multi-factor authentication requirements for all administrative and user sessions.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The vulnerability presents a high risk to organizational security by undermining the integrity of identity federation. Security teams should prioritize patching the affected Red Hat build of Keycloak instances immediately to prevent unauthorized access and potential identity-based attacks.
More Red Hat CVEs
Sources
Originally found and disclosed by Red Hat would like to thank Joy Gilbert and Reynaldo Immanuel for reporting this issue., per the CVE Program record.
- RHSA-2026:3925 Vendor advisory
- RHSA-2026:3926 Vendor advisory
- RHSA-2026:3947 Vendor advisory
- RHSA-2026:3948 Vendor advisory
- Vulnerability database entry
- RHBZ#2440300 Issue tracker