Improper Validation of Specified Type of Input in Keycloak - CVE-2026-2092
Published: June 1, 2026 / Updated: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access and disclose sensitive information.
The vulnerability exists due to improper validation of specified type of input in the SAML broker endpoint when processing encrypted assertions in an unsigned SAML response. A remote user can craft a malicious SAML response containing an encrypted assertion for an arbitrary principal to gain unauthorized access and disclose sensitive information.
Exploitation requires a valid signed SAML assertion.
Affected software
Optim
Red Hat build of Keycloak
How to mitigate CVE-2026-2092
Optim - update to 2.0.0
Red Hat build of Keycloak - addressed in versions 26.2.14, 26.4.10