Description

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

INFO

Published Date :

2026-03-18T01:14:53.540Z

Last Modified :

2026-03-18T14:10:10.355Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-2603 vulnerability.

Vendors Products
Keycloak
  • Keycloak
Redhat
  • Build Keycloak

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact