Improper access control in Keycloak - CVE-2026-2603
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to authenticate users into the realm through a disabled SAML identity provider.
The vulnerability exists due to improper enforcement of disabled identity provider status in the SAML broker callback endpoint when processing IdP-initiated broker logins. A remote attacker can submit a SAML response through the broker callback endpoint to authenticate users into the realm through a disabled SAML identity provider.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2026-2603
Red Hat build of Keycloak - addressed in versions 26.2.14, 26.4.10