CVE-2026-16443
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4.14-1 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-22 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.4 | 26.4-22 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6.5-1 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-11 < * | unaffected |
| Red Hat | Red Hat build of Keycloak 26.6 | 26.6-11 < * | unaffected |
Weaknesses
- CWE-347: Improper Verification of Cryptographic Signature
Workarounds
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/errata/RHSA-2026:50846
- https://access.redhat.com/errata/RHSA-2026:50847
- https://access.redhat.com/errata/RHSA-2026:50848
- https://access.redhat.com/errata/RHSA-2026:50849
- https://access.redhat.com/security/cve/CVE-2026-16443
- https://bugzilla.redhat.com/show_bug.cgi?id=2503139
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.