Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4p7-7chp-64hq

Опубликовано: 18 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Keycloak: Unauthorized authentication via disabled SAML Identity Provider

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 26.5.5

Отсутствует

Наименование

org.keycloak:keycloak-server-spi-private

maven
Затронутые версииВерсия исправления

<= 26.5.5

Отсутствует

EPSS

Процентиль: 38%
0.00172
Низкий

8.1 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.1
redhat
23 дня назад

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

CVSS3: 8.1
nvd
10 дней назад

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

CVSS3: 8.1
debian
10 дней назад

A flaw was found in Keycloak. A remote attacker could bypass security ...

EPSS

Процентиль: 38%
0.00172
Низкий

8.1 High

CVSS3

Дефекты

CWE-306