SAML Protocol Flaw in Keycloak Affects Open-Source Identity Management
CVE-2026-18217

3.4LOW

What is CVE-2026-18217?

A vulnerability exists within the SAML protocol implementation of Keycloak, allowing attackers to exploit configurations with wildcard redirect URLs. This flaw enables an attacker to craft a malicious SAML authentication request. When a legitimate user attempts to log in, Keycloak appends its valid response to these malicious parameters, which may mislead service providers to process incorrect data. Consequently, this could result in users mistakenly gaining access to unauthorized accounts.

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank yd1ng for reporting this issue.
.