Improper Verification of Cryptographic Signature in Keycloak - CVE-2026-16443
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to a user account.
The vulnerability exists due to improper verification of cryptographic signature in the SAML metadata import functionality of the keycloak-services component when importing identity provider metadata that lacks specific usage attributes for keys. A remote attacker can forge a SAML response to gain unauthorized access to a user account.
Exploitation requires knowledge of the target user's external identifier.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-16443
Red Hat build of Keycloak - update to 26.6.5