Improper Verification of Cryptographic Signature in Keycloak - CVE-2026-16443
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to a user account.
The vulnerability exists due to improper verification of cryptographic signature in the SAML metadata import functionality of the keycloak-services component when importing identity provider metadata that lacks specific usage attributes for keys. A remote attacker can forge a SAML response to gain unauthorized access to a user account.
Exploitation requires knowledge of the target user\'s external identifier.