Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-18967

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 6.4
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:-:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*

EPSS

Процентиль: 4%
0.00144
Низкий

6.4 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 6.4
redhat
17 дней назад

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

CVSS3: 6.4
debian
11 дней назад

A flaw was found in the SAML broker component of Keycloak, an identity ...

CVSS3: 6.4
github
11 дней назад

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

EPSS

Процентиль: 4%
0.00144
Низкий

6.4 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-294