SB2026060134 - Information disclosure in Keycloak



SB2026060134 - Information disclosure in Keycloak

Published: June 1, 2026

Security Bulletin ID SB2026060134
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Validation of Specified Type of Input (CVE-ID: CVE-2026-2092)

CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to gain unauthorized access and disclose sensitive information.

The vulnerability exists due to improper validation of specified type of input in the SAML broker endpoint when processing encrypted assertions in an unsigned SAML response. A remote user can craft a malicious SAML response containing an encrypted assertion for an arbitrary principal to gain unauthorized access and disclose sensitive information.

Exploitation requires a valid signed SAML assertion.


Remediation

Install update from vendor's website.