Back

CRITICAL

Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction

Published Aug 5, 2026

Description

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Red Hat statement

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it allows for an authentication bypass. Successful exploitation allows an attacker to obtain a full authenticated session as a linked local user, bypassing administrative restrictions. The vulnerability's root cause is the lack of enforcement of the link-only configuration within the SAML IdP-initiated SSO endpoint.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 5, 2026
Updated Aug 31, 2026
Reserved Jul 21, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Aug 10, 2026
Red Hat
Severity Important
Public date Aug 5, 2026