CVE-2026-2603
Java vulnerability analysis and mitigation

Overview

CVE-2026-2603 is an authentication bypass vulnerability in Keycloak's SAML Identity Provider (IdP) brokering functionality, described as "Unauthorized authentication via disabled SAML Identity Provider." A remote attacker with low-level credentials can send a valid SAML response from an external IdP to the Keycloak SAML endpoint for IdP-initiated broker logins, completing authentication even when the SAML Identity Provider has been explicitly disabled. The vulnerability affects Red Hat build of Keycloak 26.2.x (fixed in 26.2.14) and 26.4.x (fixed in 26.4.10). It was disclosed on March 5, 2026, with NVD publication on March 18, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Red Hat CVE, Red Hat RHSA-2026:3926).

Technical details

The root cause is classified as CWE-306 (Missing Authentication for Critical Function): Keycloak's IdentityBrokerService fails to enforce the disabled state of a SAML Identity Provider when processing IdP-initiated login flows. An attacker who possesses (or can obtain) a valid SAML response from the external IdP can submit it directly to the Keycloak SAML broker endpoint, bypassing the administrative control that disables the IdP. The attack is network-based, requires low privileges (a valid SAML assertion from the IdP), and requires no user interaction. No public proof-of-concept code has been identified at this time (Red Hat CVE, Red Hat RHSA-2026:3947).

Impact

Successful exploitation allows an attacker to authenticate to Keycloak-protected applications as a legitimate user despite the associated SAML Identity Provider being administratively disabled, resulting in high confidentiality and high integrity impact. This could expose sensitive application data, allow unauthorized modification of user-accessible resources, and undermine access revocation controls — for example, in scenarios where an IdP is disabled to cut off a compromised or terminated user's access. Availability is not directly impacted. The scope is limited to the affected Keycloak realm and its downstream applications (Red Hat CVE, Red Hat RHSA-2026:3925).

Exploitation steps

  1. Reconnaissance: Identify a target Keycloak deployment (Red Hat build of Keycloak 26.2.x prior to 26.2.14 or 26.4.x prior to 26.4.10) with a SAML Identity Provider configured but administratively disabled.
  2. Obtain a valid SAML response: Authenticate to the external SAML Identity Provider directly (using valid credentials or a previously captured/replayed SAML assertion) to obtain a signed SAML response.
  3. Submit to Keycloak SAML broker endpoint: Send an HTTP POST request containing the valid SAML response to the Keycloak IdP-initiated broker login endpoint (e.g., /realms/{realm}/broker/{idp-alias}/endpoint) without triggering the disabled-IdP check.
  4. Complete unauthorized authentication: Keycloak processes the SAML response without verifying the IdP's disabled status, establishing an authenticated session for the attacker as the identity asserted in the SAML response.
  5. Access protected resources: Use the resulting Keycloak session token to access applications and APIs protected by the compromised realm (Red Hat CVE, Red Hat RHSA-2026:3947).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /realms/{realm}/broker/{disabled-idp-alias}/endpoint originating from external or unexpected IP addresses; SAML responses submitted to Keycloak broker endpoints outside of normal business hours or from unusual source IPs.
  • Logs: Keycloak server logs showing successful IdP-initiated broker logins for a SAML Identity Provider that is marked as disabled in the realm configuration; authentication events in Keycloak audit logs (LOGIN events) associated with a disabled IdP alias.
  • Application: Unexpected active sessions in Keycloak for users whose access should have been revoked via IdP disablement; session tokens issued for identities linked to a disabled SAML provider.

Mitigation and workarounds

Red Hat has released patched versions addressing this vulnerability: Red Hat build of Keycloak 26.2.14 (packages: RHSA-2026:3926; container images: RHSA-2026:3925) and Red Hat build of Keycloak 26.4.10 (packages: RHSA-2026:3947; container images: RHSA-2026:3948). Organizations should upgrade to these versions as the primary remediation. As an interim workaround, administrators can remove or fully delete (rather than disable) SAML Identity Provider configurations that should no longer be active, and implement network-level controls to restrict access to Keycloak broker endpoints. Back up all configurations and databases before applying updates (Red Hat RHSA-2026:3926, Red Hat RHSA-2026:3947).

Community reactions

Red Hat classified this advisory as Important severity and released coordinated patches across both the 26.2 and 26.4 release streams on March 5, 2026. The vulnerability was also tracked by the upstream Keycloak project (GitHub release 26.5.5 references) and indexed by ENISA's European Vulnerability Database (EUVD-2026-12690). Community aggregators including RedPacket Security and VulnDB noted the disclosure, and the vulnerability received coverage in Java ecosystem news roundups. No significant controversy or researcher commentary beyond standard disclosure has been observed (Red Hat RHSA-2026:3925, ENISA EUVD).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-p279-2cqp-84jgCRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesJul 24, 2026
GHSA-fp43-vj7g-pg92HIGH7.5
  • Java logoJava
  • org.omnifaces:omnifaces
NoYesJul 24, 2026
GHSA-7ppr-r889-mcf2HIGH7.5
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.12
NoYesJul 24, 2026
GHSA-mhvj-jhpq-885vHIGH7.4
  • Java logoJava
  • org.http4s:http4s-blaze-server_2.13
NoYesJul 24, 2026
GHSA-46q4-43ph-c6frHIGH7.4
  • Java logoJava
  • org.http4s:blaze-http_2.12
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management