Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
Fixed in: 26.2.14, 26.4.10, 26.5.5, 26.6.0
details
- Finding IDs
- F-KEYCLOAK-SAML-001
- CVE
- CVE-2026-2092
- GHSA
- GHSA-794g-x443-36f7
- Status
- patched
- CWE
- CWE-1287
- Fixed in
- 26.2.14, 26.4.10, 26.5.5, 26.6.0
- Recorded credit
- reporter: @1seal
- Note
- GHSA-794g-x443-36f7; improper validation of encrypted SAML assertions can allow unauthorized access via crafted SAML response.
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
- Upstream CWE
- CWE-1287
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-KEYCLOAK-SAML-001: Verification failures. Encrypted SAML assertion handling bypasses required validation. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-KEYCLOAK-SAML-001
Security area (1seal assessment): Identity. Insufficient validation of encrypted SAML assertions permits unauthorized authentication; the affected property is the asserted user identity. Reviewed 24 Sep 2026.