CVE-2026-16442
Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction
Record summary
CVE-2026-16442 has a selected CVSS score of 7.4 (high).
Description
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
Showing 12 of 14| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Version data not supplied | |
Red Hat JBoss Enterprise Application Platform Expansion PackBrowse Red Hat / Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesDefault status: unaffected | CVE List | Version data not supplied | |
Default status: unaffected | CVE List | Version data not supplied | |
Red Hat build of Keycloak 26.4Browse Red Hat / Red Hat build of Keycloak 26.4rhbk/keycloak-operator-bundleDefault status: affected | CVE List | 26.4.14-1 to < * | unaffected |
Default status: affected | CVE List | 26.4-22 to < * | unaffected |
Red Hat build of Keycloak 26.4Browse Red Hat / Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9-operatorDefault status: affected | CVE List | 26.4-22 to < * | unaffected |
Red Hat build of Keycloak 26.4.14Browse Red Hat / Red Hat build of Keycloak 26.4.14keycloak-servicesDefault status: unaffected | CVE List | Version data not supplied | |
Red Hat build of Keycloak 26.4.14Browse Red Hat / Red Hat build of Keycloak 26.4.14rhbk-openshift-rhel9/rhbk-openshift-rhel9Default status: unaffected | CVE List | Version data not supplied | |
Red Hat build of Keycloak 26.6Browse Red Hat / Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleDefault status: affected | CVE List | 26.6.5-1 to < * | unaffected |
Default status: affected | CVE List | 26.6-11 to < * | unaffected |
Red Hat build of Keycloak 26.6Browse Red Hat / Red Hat build of Keycloak 26.6rhbk/keycloak-rhel9-operatorDefault status: affected | CVE List | 26.6-11 to < * | unaffected |
Default status: unaffected | CVE List | Version data not supplied | |