SB2026060134 - Information disclosure in Keycloak
Published: June 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Validation of Specified Type of Input (CVE-ID: CVE-2026-2092)
CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to gain unauthorized access and disclose sensitive information.
The vulnerability exists due to improper validation of specified type of input in the SAML broker endpoint when processing encrypted assertions in an unsigned SAML response. A remote user can craft a malicious SAML response containing an encrypted assertion for an arbitrary principal to gain unauthorized access and disclose sensitive information.
Exploitation requires a valid signed SAML assertion.
Remediation
Install update from vendor's website.