CVE-2026-18967: Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow
A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If using Keycloak SAML broker with the IdP-Initiated flow, mitigate the one-time-use assertion replay risk by preventing use of captured SAML assertions (e.g., disable/avoid the SAML broker IdP-Initiated configuration until a fix is applied).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18967?
The severity of CVE-2026-18967 is rated as medium with a score of 6.4.
How do I fix CVE-2026-18967?
To fix CVE-2026-18967, ensure that your Keycloak configuration enforces the OneTimeUse condition for SAML assertions.
What systems are affected by CVE-2026-18967?
CVE-2026-18967 affects the Keycloak services when configured as a SAML broker in the IdP-Initiated flow.
What type of attack can occur due to CVE-2026-18967?
CVE-2026-18967 allows attackers to replay valid, unused SAML assertions to gain unauthorized access.
What component of Keycloak is vulnerable in CVE-2026-18967?
The SAML broker component of Keycloak is vulnerable in CVE-2026-18967.