CVE-2026-3047
8.8Red Hat · Red Hat build of Keycloak
A SAML authentication bypass vulnerability in Red Hat build of Keycloak allows disabled Identity Provider clients to establish unauthorized SSO sessions.
Executive summary
A critical authentication bypass flaw in Red Hat build of Keycloak allows attackers to establish unauthorized SSO sessions, potentially leading to full account compromise.
Vulnerability
This flaw exists in the SAML broker component where a disabled SAML client, when used as an IdP-initiated broker landing target, incorrectly allows the completion of the login process. The attacker requires low privileges and can leverage this to gain unauthorized access to other enabled clients without proper authentication.
Business impact
The ability to bypass authentication mechanisms poses a severe risk to organizational security, as it permits unauthorized access to protected applications and sensitive data. With a CVSS score of 8.8, this vulnerability is classified as High severity, indicating a significant potential for lateral movement and compromise of user identities within the SSO environment.
Remediation
Immediate Action: Update the Red Hat build of Keycloak to the versions specified in the relevant security advisories, specifically 26.2.14-1 or 26.2-16 for the 26.2 branch, and 26.4.10-1 or 26.4-12 for the 26.4 branch.
Proactive Monitoring: Review authentication and SSO logs for anomalous login patterns or successful sessions originating from disabled identity providers.
Compensating Controls: Ensure that SAML client configurations are strictly audited and that unnecessary identity providers are removed or disabled at the network or application firewall level if immediate patching is not feasible.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for unauthorized access across the SSO ecosystem, this vulnerability represents a significant security risk. Administrators must prioritize the application of the provided Red Hat security updates to restore the integrity of the authentication process and prevent potential session hijacking.
More Red Hat CVEs
Sources
- RHSA-2026:3925 Vendor advisory
- RHSA-2026:3926 Vendor advisory
- RHSA-2026:3947 Vendor advisory
- RHSA-2026:3948 Vendor advisory
- Vulnerability database entry
- RHBZ#2441966 Issue tracker