Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16442

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it allows for an authentication bypass. Successful exploitation allows an attacker to obtain a full authenticated session as a linked local user, bypassing administrative restrictions. The vulnerability's root cause is the lack of enforcement of the link-only configuration within the SAML IdP-initiated SSO endpoint.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected
Red Hat build of Keycloak 26.4rhbk/keycloak-operator-bundleFixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9FixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9-operatorFixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4.14keycloak-servicesFixedRHSA-2026:5084605.08.2026
Red Hat build of Keycloak 26.4.14rhbk-openshift-rhel9/rhbk-openshift-rhel9FixedRHSA-2026:5084605.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleFixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9FixedRHSA-2026:5084905.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2503138keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link-only restriction

EPSS

Процентиль: 10%
0.00202
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
12 дней назад

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

CVSS3: 7.4
debian
12 дней назад

A flaw was found in the SAML broker component of Keycloak, which is us ...

CVSS3: 7.4
github
12 дней назад

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

EPSS

Процентиль: 10%
0.00202
Низкий

7.4 High

CVSS3

Уязвимость CVE-2026-16442