Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18967

Опубликовано: 31 июл. 2026
Источник: redhat
CVSS3: 6.4

Описание

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to capture a valid SAML assertion and replay it within a specific time window, and it only affects the IdP-Initiated broker flow. Successful exploitation allows an attacker to hijack a user's session and perform actions with their privileges. The vulnerability's root cause is the failure to record and check SAML assertion IDs for the OneTimeUse condition.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesAffected
Red Hat Build of Keycloakrhbk-keycloak-rhel9/rhbk-keycloak-rhel9Affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesFix deferred
Red Hat Single Sign-On 7keycloak-servicesNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-294
https://bugzilla.redhat.com/show_bug.cgi?id=2511604keycloak-services: keycloak-services: SAML OneTimeUse assertion replay in IdP-Initiated broker flow

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
nvd
11 дней назад

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

CVSS3: 6.4
debian
11 дней назад

A flaw was found in the SAML broker component of Keycloak, an identity ...

CVSS3: 6.4
github
11 дней назад

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

6.4 Medium

CVSS3