CVE-2026-16442
Received Received - Intake

Keycloak SAML Broker Account Linking Bypass

Vulnerability report for CVE-2026-16442, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Red Hat, Inc.

Description

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat keycloak *
redhat keycloak_services *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's SAML broker component. It allows an attacker who controls a linked upstream identity provider to bypass login restrictions and gain full access to a local user account. The issue occurs because the IdP-initiated Single Sign-On endpoint does not check if a provider is restricted to account linking only.

Detection Guidance

Check Keycloak logs for unusual SAML IdP-initiated SSO attempts at the endpoint /realms/{realm}/broker/{alias}/endpoint/clients/{client_id}. Monitor for successful authentications from upstream providers configured with linkOnly=true.

Impact Analysis

An attacker could exploit this to gain unauthorized access to a local user account, potentially leading to data breaches, privilege escalation, or unauthorized actions within the system. The impact includes high confidentiality and integrity risks as per the CVSS score of 7.4.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements such as GDPR's data protection principles or HIPAA's access controls. Non-compliance risks include legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Disable IdP-initiated SSO for SAML brokers configured with linkOnly=true. Restrict access to the vulnerable endpoint via network policies or reverse proxy rules until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16442. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart