Flaw in Identity Brokering of Keycloak by Red Hat
CVE-2026-16443
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-16443?
A flaw has been identified in the SAML metadata import functionality of the keycloak-services component, which is essential for identity brokering in Red Hat Build of Keycloak. The vulnerability occurs when importing identity provider metadata that does not include specific usage attributes for keys. As a result, the system may erroneously disable signature validation for SAML responses even if a signing certificate is present. This issue poses a risk by allowing an unauthenticated attacker to forge a SAML response, potentially gaining unauthorized access to user accounts by exploiting knowledge of an external identifier.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4.14-1
Red Hat build of Keycloak 26.4 26.4-22
Red Hat build of Keycloak 26.4 26.4-22
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved