Flaw in Identity Brokering of Keycloak by Red Hat
CVE-2026-16443

7.4HIGH

What is CVE-2026-16443?

A flaw has been identified in the SAML metadata import functionality of the keycloak-services component, which is essential for identity brokering in Red Hat Build of Keycloak. The vulnerability occurs when importing identity provider metadata that does not include specific usage attributes for keys. As a result, the system may erroneously disable signature validation for SAML responses even if a signing certificate is present. This issue poses a risk by allowing an unauthenticated attacker to forge a SAML response, potentially gaining unauthorized access to user accounts by exploiting knowledge of an external identifier.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli (Trail of Bits) for reporting this issue.
.