
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2092 is an improper validation of encrypted SAML assertions vulnerability in Keycloak's SAML broker endpoint. The flaw allows an attacker with a valid signed SAML assertion to craft a malicious SAML response and inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure. It was disclosed on March 5, 2026, and affects Red Hat build of Keycloak versions 26.2.x (prior to 26.2.14) and 26.4.x (prior to 26.4.10). The vulnerability carries a CVSS v3.1 base score of 7.7 (High) (Red Hat CVE, Red Hat Bugzilla).
The root cause is classified as CWE-1287 (Improper Validation of Specified Type of Input). Keycloak's SAML broker endpoint fails to properly validate encrypted assertions when the overall SAML response is unsigned — it validates the inner assertion's signature but does not enforce that the enclosing SAML response itself is signed. An attacker who possesses a legitimately signed SAML assertion can strip it from its original response, wrap it in a crafted unsigned SAML response, and inject an encrypted assertion for a different (arbitrary) principal. Exploitation requires the attacker to hold low-level authenticated privileges and operate over the network, with high attack complexity (Red Hat CVE, Red Hat Bugzilla).
Successful exploitation allows an attacker to impersonate arbitrary principals within Keycloak-federated applications, resulting in unauthorized access to protected resources and potential exposure of sensitive user data (high confidentiality impact). The vulnerability has a changed scope, meaning it can affect resources and services beyond the Keycloak instance itself — including downstream applications relying on SAML-based single sign-on. Integrity and availability impacts are assessed as low, with limited potential for data modification or service disruption (Red Hat CVE, RHSA-2026:3926).
<samlp:Response> element) but contains an encrypted <saml:EncryptedAssertion> element targeting an arbitrary principal (e.g., an administrator account)./realms/{realm}/broker/{idp-alias}/endpoint)./realms/{realm}/broker/{idp-alias}/endpoint).<ds:Signature> element at the response level but containing <saml:EncryptedAssertion> elements.Red Hat has released patched versions addressing this vulnerability: Red Hat build of Keycloak 26.2.14 (packages: RHSA-2026:3926; images: RHSA-2026:3925) and Red Hat build of Keycloak 26.4.10 (packages: RHSA-2026:3947; images: RHSA-2026:3948). Upstream Keycloak 26.5.5 also includes the fix. Organizations should upgrade to a patched version as the primary remediation. As a temporary workaround, consider requiring signed SAML responses at the IdP level and restricting access to the Keycloak SAML broker endpoint to trusted network sources only (RHSA-2026:3925, RHSA-2026:3947).
Red Hat rated this advisory as "Important" severity and released patches on March 5, 2026, alongside fixes for several other Keycloak SAML-related vulnerabilities. The vulnerability received brief coverage in Java ecosystem news roundups (InfoQ, TechLife Blog) in the week following disclosure. Social media activity was limited, with automated security alert accounts (RedPacketSecurity) sharing the advisory on Mastodon and X. No significant independent researcher commentary or detailed technical write-ups have been published as of the available data (RHSA-2026:3926).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."