CVE-2026-18967
Received Received - Intake

SAML Assertion Replay in Keycloak IdP-Initiated Flow

Vulnerability report for CVE-2026-18967, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: Red Hat, Inc.

Description

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat keycloak *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-294 A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Keycloak's SAML broker component. When configured for IdP-Initiated flow, it fails to enforce the OneTimeUse condition in SAML assertions. This allows attackers to replay captured valid assertions multiple times, potentially hijacking user sessions and gaining unauthorized access.

Detection Guidance

To detect this vulnerability, monitor Keycloak logs for SAML assertion replay attempts or unusual session activity. Check for multiple uses of the same SAML assertion ID in IdP-Initiated flow logs. No specific commands are provided in the context, but inspecting SAML assertion logs and network traffic for duplicate assertions may help.

Impact Analysis

An attacker could capture a valid SAML assertion and replay it to impersonate a user, gaining unauthorized access to systems with that user's privileges. Exploitation requires capturing the assertion and replaying it within a specific time window.

Mitigation Strategies

Since mitigation options are unavailable or unstable per Red Hat, consider disabling the IdP-Initiated SAML broker flow in Keycloak as a temporary workaround. Monitor Red Hat's advisories for official patches or updates. Ensure network segmentation to limit exposure to potential attackers capturing SAML assertions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18967. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart