A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Red Hat
Red Hat red Hat Build Of Keycloak 26.2 Red Hat red Hat Build Of Keycloak 26.2.14 Red Hat red Hat Build Of Keycloak 26.4 Red Hat red Hat Build Of Keycloak 26.4.10 |
|
| Vendors & Products |
Red Hat
Red Hat red Hat Build Of Keycloak 26.2 Red Hat red Hat Build Of Keycloak 26.2.14 Red Hat red Hat Build Of Keycloak 26.4 Red Hat red Hat Build Of Keycloak 26.4.10 |
Fri, 06 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 05 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26.2::el9 | |
| References |
|
Thu, 05 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak:26.4::el9 | |
| References |
|
Thu, 05 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions. | |
| Title | Org.keycloak.broker.saml: keycloak saml broker: authentication bypass due to disabled saml client completing idp-initiated login | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-305 | |
| CPEs | cpe:/a:redhat:build_keycloak: | |
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-03-05T18:28:36.337Z
Updated: 2026-03-06T18:13:14.612Z
Reserved: 2026-02-23T17:30:53.926Z
Link: CVE-2026-3047
No data.
Status : Awaiting Analysis
Published: 2026-03-05T19:16:18.383
Modified: 2026-03-05T20:16:17.137
Link: CVE-2026-3047