PT-2026-23493 · Red Hat · Keycloak

Osidb Bzimport

·

Published

2026-03-05

·

Updated

2026-03-08

·

CVE-2026-3009

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the IdentityBrokerService.performLogin endpoint of Keycloak that allows authentication to continue using an Identity Provider (IdP) even after it has been administratively disabled. An attacker with knowledge of the IdP alias can reuse a previous login request to circumvent the administrative restriction. This bypasses access control enforcement, potentially enabling unauthorized authentication through a disabled external provider.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3009
GHSA-M297-3JV9-M927

Affected Products

Keycloak