Improper access control in Keycloak - CVE-2026-3009
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to authenticate through a disabled identity provider.
The vulnerability exists due to improper enforcement of disabled identity provider status in the IdentityBrokerService.performLogin endpoint when processing broker login requests. A remote user can submit a manually constructed request to the broker login endpoint to authenticate through a disabled identity provider.
Exploitation requires a valid session_code and tab_id obtained from a standard login attempt.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-3009
Red Hat build of Keycloak - update to 26.4.10