CVE-2026-16442

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-05 16:16

Updated : 2026-08-10 19:21


NVD link : CVE-2026-16442

Mitre link : CVE-2026-16442

CVE.ORG link : CVE-2026-16442


JSON object : View

Products Affected

redhat

  • build_of_keycloak
CWE
CWE-346

Origin Validation Error