Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-2603

Опубликовано: 18 мар. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

EPSS

Процентиль: 34%
0.00413
Низкий

8.1 High

CVSS3

Дефекты

CWE-306
CWE-306

Связанные уязвимости

CVSS3: 8.1
redhat
5 месяцев назад

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

CVSS3: 8.1
debian
5 месяцев назад

A flaw was found in Keycloak. A remote attacker could bypass security ...

CVSS3: 8.1
github
5 месяцев назад

Keycloak: Unauthorized authentication via disabled SAML Identity Provider

EPSS

Процентиль: 34%
0.00413
Низкий

8.1 High

CVSS3

Дефекты

CWE-306
CWE-306