Improper access control in Keycloak - CVE-2026-3047
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to bypass disabled SAML client restrictions and establish a realm SSO session.
The vulnerability exists due to improper enforcement of disabled client status in the SAML broker when processing IdP-initiated broker logins. A remote user can authenticate through an external identity provider to bypass disabled SAML client restrictions and establish a realm SSO session.
The disabled SAML client must be configured as an IdP-initiated broker landing target.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-3047
Red Hat build of Keycloak - addressed in versions 26.2.14, 26.4.10