SAML Assertion Replay Vulnerability in Keycloak Identity Management
CVE-2026-18967

6.4MEDIUM

What is CVE-2026-18967?

A vulnerability exists in Keycloak's SAML broker component where the OneTimeUse condition in SAML assertions is not enforced when using the IdP-Initiated flow. This oversight allows attackers to capture valid, unused assertions and reuse them to hijack user sessions, potentially granting unauthorized access to the system. Proper configuration and timely updates are crucial to protect against this risk.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Lidor Vasker for reporting this issue.
.