Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16443

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.4

Описание

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it allows for unauthenticated account takeover under common configuration scenarios. Successful exploitation allows an attacker to impersonate users and gain full access to their accounts by forging SAML responses. The vulnerability's root cause is an improper configuration of signature validation settings during the SAML IdP metadata import process.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected
Red Hat build of Keycloak 26.4rhbk/keycloak-operator-bundleFixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9FixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9-operatorFixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4.14keycloak-servicesFixedRHSA-2026:5084605.08.2026
Red Hat build of Keycloak 26.4.14rhbk-openshift-rhel9/rhbk-openshift-rhel9FixedRHSA-2026:5084605.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleFixedRHSA-2026:5084905.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9FixedRHSA-2026:5084905.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2503139keycloak-services: keycloak-services: SAML broker metadata import disables response signature validation

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
12 дней назад

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

CVSS3: 7.4
debian
12 дней назад

A flaw was found in the SAML metadata import functionality of the keyc ...

CVSS3: 7.4
github
12 дней назад

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

7.4 High

CVSS3