User Authentication Bypass Vulnerability in Keycloak by Red Hat
CVE-2026-16442
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-16442?
A vulnerability has been identified in the SAML broker component of Keycloak, which is critical for managing identity federation and user authentication. The flaw arises from the IdP-initiated Single Sign-On endpoint's failure to validate whether a provider is restricted to account linking. This oversight may enable an attacker controlling a linked upstream identity to circumvent login restrictions, potentially granting unauthorized access to the local user account. Organizations utilizing Keycloak should ensure they are running the latest version and apply any available patches to mitigate this security risk.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4-22
Red Hat build of Keycloak 26.4 26.4-22
Red Hat build of Keycloak 26.4 26.4.14-1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved