CVE-2026-2603
HIGH8.1EPSS 0.23%Keycloak: Unauthorized authentication via disabled SAML Identity Provider
Published: 3/18/2026Modified: 5/20/2026
Description
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.
Affected packages (2)
- Maven/org.keycloak:keycloak-server-spi-privatefrom 0, < 26.5.5
- Maven/org.keycloak:keycloak-servicesfrom 0, < 26.5.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
References (13)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2026-2603
- PATCHhttps://github.com/keycloak/keycloak
- WEBhttps://access.redhat.com/errata/RHSA-2026:3925
- WEBhttps://access.redhat.com/errata/RHSA-2026:3926
- WEBhttps://access.redhat.com/errata/RHSA-2026:3947
- WEBhttps://access.redhat.com/errata/RHSA-2026:3948
- WEBhttps://access.redhat.com/security/cve/CVE-2026-2603
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=2440300
- WEBhttps://github.com/keycloak/keycloak/commit/4fd5367e6cc28cfa68fb2240fc459c12b1fdbf2a
- WEBhttps://github.com/keycloak/keycloak/commit/8ed7e59dc08d79751a27c23aadb590f06b43f132
- WEBhttps://github.com/keycloak/keycloak/commits/26.5.5
- WEBhttps://github.com/keycloak/keycloak/issues/46911
- WEBhttps://github.com/keycloak/keycloak/pull/46932