CVE-2026-2603

8.1

Red Hat · Red Hat build of Keycloak

A flaw in Keycloak allows remote, authenticated attackers to bypass security controls by sending valid SAML responses to the SAML endpoint for IdP-initiated broker logins.

Executive summary

A vulnerability in the Red Hat build of Keycloak allows authenticated attackers to bypass security controls and perform unauthorized logins, posing a significant risk to identity management systems.

Vulnerability

This is a case of missing authentication for a critical function (CWE-306). A remote attacker with existing low-level user privileges can exploit this flaw to bypass authentication checks for IdP-initiated broker logins, even when the specific Identity Provider is disabled.

Business impact

The ability to perform unauthorized authentication against an identity provider can lead to full account takeover or unauthorized access to protected applications. Given the CVSS score of 8.1, this represents a high-severity risk that could lead to widespread data compromise or lateral movement within the enterprise environment.

Remediation

Immediate Action: Update the Red Hat build of Keycloak to the versions specified in the vendor errata (RHSA-2026:3925, RHSA-2026:3926, RHSA-2026:3947, or RHSA-2026:3948) depending on your current deployment branch.

Proactive Monitoring: Monitor authentication logs for suspicious IdP-initiated login patterns, particularly those originating from disabled or unexpected SAML Identity Providers.

Compensating Controls: Ensure that strict network-level access controls are in place for the SAML endpoint and consider implementing additional multi-factor authentication requirements for all administrative and user sessions.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability presents a high risk to organizational security by undermining the integrity of identity federation. Security teams should prioritize patching the affected Red Hat build of Keycloak instances immediately to prevent unauthorized access and potential identity-based attacks.

More Red Hat CVEs

Sources

Originally found and disclosed by Red Hat would like to thank Joy Gilbert and Reynaldo Immanuel for reporting this issue., per the CVE Program record.