CVE-2026-2603: Keycloak: keycloak: unauthorized authentication via disabled saml identity provider

Published Feb 16, 2026
·
Updated

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

Other sources

Summary: A SAML Identity Provider that is disabled in the broker realm can still complete IdP‑initiated broker logins

Requirements to exploit:

The SAML protocol endpoint must be reachable Attacker needs to know the URL assigned to the broker in Keycloak for IDP initiated Attacker needs to log in with a valid user to the external IDP via SAML to be able to send a SAML response to Keycloak As the SAML IDP is disabled and no longer trusted, this violates C&A for Keycloak.

Steps to reproduce:

Target a Keycloak 26.5.2 instance. Set up an IDP in Keycloak that is disabled Generate a valid SAML response from the external IdP Send it to the Keycloak SAML endpoint for IDP initiated broker logins

Red Hat

Affected Software

5 affected components
Red Hat Keycloak
maven/org.keycloak:keycloak-server-spi-private<=26.5.5
maven/org.keycloak:keycloak-services<=26.5.5
redhat Build Of Keycloak>=26.2<26.2.14
redhat Build Of Keycloak>=26.4<26.4.10

Event History

Feb 16, 2026
Data Sourced
via Red Hat·09:18 PM
DescriptionSeverityAffected Software
Mar 18, 2026
CVE Published
via MITRE·01:14 AM
Data Sourced
via MITRE·01:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
Affected Software
Advisory Published
via GitHub·03:32 AM
Data Sourced
via GitHub·03:32 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-2603?

CVE-2026-2603 has been classified with high severity due to its potential for unauthorized access through a disabled SAML identity provider.

2

How do I fix CVE-2026-2603?

To fix CVE-2026-2603, update your Keycloak installation to version 26.5.6 or later where the vulnerability has been addressed.

3

What are the affected versions for CVE-2026-2603?

CVE-2026-2603 affects Red Hat Keycloak versions up to and including 26.5.5.

4

Can CVE-2026-2603 be exploited remotely?

Yes, CVE-2026-2603 can be exploited remotely by an attacker sending a valid SAML response to Keycloak's SAML endpoint.

5

Is user authentication compromised due to CVE-2026-2603?

Yes, CVE-2026-2603 allows unauthorized authentication, potentially compromising user authentication through disabled identity providers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203