Insufficient Session Expiration in Keycloak - CVE-2026-1190
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to extend the validity period of SAML responses.
The vulnerability exists due to missing timestamp validation in Keycloak's SAML brokering functionality when processing SAML responses containing SubjectConfirmationData. A remote attacker can delay expiration of a SAML response to extend the time it is considered valid.
User interaction is required.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-1190
Red Hat build of Keycloak - update to 26.4.10