
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1190 is a missing XML validation flaw in Keycloak's SAML brokering functionality, specifically affecting the org.keycloak/keycloak-services component. When Keycloak is configured as a SAML client (SAML brokering), it fails to validate the NotOnOrAfter timestamp within the SubjectConfirmationData element of SAML responses, allowing an attacker to delay a SAML response beyond its intended validity window. This can result in unexpected session durations or resource consumption. The vulnerability was reported on January 19, 2026, and published by Red Hat on January 26, 2026, with patches released on March 5, 2026. It carries a CVSS v3.1 base score of 3.1 (Low) (Red Hat CVE, Red Hat Bugzilla).
The root cause is classified as CWE-112 (Missing XML Validation): Keycloak's SAML brokering code checks the NotOnOrAfter timestamp in the SAML Conditions element but omits the equivalent check in SubjectConfirmationData. An attacker who can intercept or delay a legitimate SAML response in transit can present it to Keycloak after the SubjectConfirmationData expiry time has passed, and Keycloak will still accept it as valid. Exploitation requires network access, high attack complexity, and user interaction (a legitimate user must initiate the SAML flow), and the SAML response cannot be tampered with because signature validation would fail — the attacker can only delay delivery of an already-signed response (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation has a limited integrity impact: an attacker can extend the effective validity window of a SAML response, potentially causing Keycloak to establish a session that should have been rejected due to expiry. There is no confidentiality or availability impact assessed. The practical consequence is unexpected or prolonged session durations and potential resource consumption on the Keycloak server, but the attacker cannot forge, replay to a different request, or otherwise tamper with the SAML assertion due to signature enforcement (Red Hat Bugzilla, Red Hat CVE).
NotOnOrAfter time specified in SubjectConfirmationData.SubjectConfirmationData.NotOnOrAfter field, it accepts the expired response.NotOnOrAfter value in SubjectConfirmationData; look for successful authentications via SAML brokering at unexpected times./realms/<realm>/broker/<idp>/endpoint) arriving well after the expected SAML response window.Red Hat released patches addressing CVE-2026-1190 in Red Hat build of Keycloak 26.4.10 (RHSA-2026:3947 for packages, RHSA-2026:3948 for OpenShift container images), issued on March 5, 2026. The upstream Keycloak project also addressed this in the Keycloak 26.5.4 release. Administrators should upgrade to these versions or later as the primary remediation. No specific configuration-based workaround has been published; however, ensuring SAML responses are signed (which prevents tampering) limits the practical impact while patching is pending (Red Hat Advisory RHSA-2026:3947, Red Hat Advisory RHSA-2026:3948, Keycloak Releases).
The vulnerability received routine coverage from vulnerability aggregation platforms and security databases upon publication. Red Hat classified the broader advisory (RHSA-2026:3947) containing this CVE as "Important" severity due to the combination of multiple SAML-related flaws addressed together, though CVE-2026-1190 itself is rated Low individually. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified (Red Hat Advisory RHSA-2026:3947).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."