Back

CRITICAL

Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation

Published Aug 5, 2026

Description

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Red Hat statement

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it allows for unauthenticated account takeover under common configuration scenarios. Successful exploitation allows an attacker to impersonate users and gain full access to their accounts by forging SAML responses. The vulnerability's root cause is an improper configuration of signature validation settings during the SAML IdP metadata import process.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 5, 2026
Updated Aug 31, 2026
Reserved Jul 21, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Aug 10, 2026
Red Hat
Severity Important
Public date Aug 5, 2026