
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2603 is an authentication bypass vulnerability in Keycloak's SAML Identity Provider (IdP) brokering functionality, described as "Unauthorized authentication via disabled SAML Identity Provider." A remote attacker with low-level credentials can send a valid SAML response from an external IdP to the Keycloak SAML endpoint for IdP-initiated broker logins, completing authentication even when the SAML Identity Provider has been explicitly disabled. The vulnerability affects Red Hat build of Keycloak 26.2.x (fixed in 26.2.14) and 26.4.x (fixed in 26.4.10). It was disclosed on March 5, 2026, with NVD publication on March 18, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Red Hat CVE, Red Hat RHSA-2026:3926).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function): Keycloak's IdentityBrokerService fails to enforce the disabled state of a SAML Identity Provider when processing IdP-initiated login flows. An attacker who possesses (or can obtain) a valid SAML response from the external IdP can submit it directly to the Keycloak SAML broker endpoint, bypassing the administrative control that disables the IdP. The attack is network-based, requires low privileges (a valid SAML assertion from the IdP), and requires no user interaction. No public proof-of-concept code has been identified at this time (Red Hat CVE, Red Hat RHSA-2026:3947).
Successful exploitation allows an attacker to authenticate to Keycloak-protected applications as a legitimate user despite the associated SAML Identity Provider being administratively disabled, resulting in high confidentiality and high integrity impact. This could expose sensitive application data, allow unauthorized modification of user-accessible resources, and undermine access revocation controls — for example, in scenarios where an IdP is disabled to cut off a compromised or terminated user's access. Availability is not directly impacted. The scope is limited to the affected Keycloak realm and its downstream applications (Red Hat CVE, Red Hat RHSA-2026:3925).
/realms/{realm}/broker/{idp-alias}/endpoint) without triggering the disabled-IdP check./realms/{realm}/broker/{disabled-idp-alias}/endpoint originating from external or unexpected IP addresses; SAML responses submitted to Keycloak broker endpoints outside of normal business hours or from unusual source IPs.LOGIN events) associated with a disabled IdP alias.Red Hat has released patched versions addressing this vulnerability: Red Hat build of Keycloak 26.2.14 (packages: RHSA-2026:3926; container images: RHSA-2026:3925) and Red Hat build of Keycloak 26.4.10 (packages: RHSA-2026:3947; container images: RHSA-2026:3948). Organizations should upgrade to these versions as the primary remediation. As an interim workaround, administrators can remove or fully delete (rather than disable) SAML Identity Provider configurations that should no longer be active, and implement network-level controls to restrict access to Keycloak broker endpoints. Back up all configurations and databases before applying updates (Red Hat RHSA-2026:3926, Red Hat RHSA-2026:3947).
Red Hat classified this advisory as Important severity and released coordinated patches across both the 26.2 and 26.4 release streams on March 5, 2026. The vulnerability was also tracked by the upstream Keycloak project (GitHub release 26.5.5 references) and indexed by ENISA's European Vulnerability Database (EUVD-2026-12690). Community aggregators including RedPacket Security and VulnDB noted the disclosure, and the vulnerability received coverage in Java ecosystem news roundups. No significant controversy or researcher commentary beyond standard disclosure has been observed (Red Hat RHSA-2026:3925, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."