User Authentication Bypass Vulnerability in Keycloak by Red Hat
CVE-2026-16442

7.4HIGH

What is CVE-2026-16442?

A vulnerability has been identified in the SAML broker component of Keycloak, which is critical for managing identity federation and user authentication. The flaw arises from the IdP-initiated Single Sign-On endpoint's failure to validate whether a provider is restricted to account linking. This oversight may enable an attacker controlling a linked upstream identity to circumvent login restrictions, potentially granting unauthorized access to the local user account. Organizations utilizing Keycloak should ensure they are running the latest version and apply any available patches to mitigate this security risk.

Affected Version(s)

Red Hat build of Keycloak 26.4 26.4-22

Red Hat build of Keycloak 26.4 26.4-22

Red Hat build of Keycloak 26.4 26.4.14-1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.