PT-2026-23493 · Red Hat · Keycloak
Osidb Bzimport
·
Published
2026-03-05
·
Updated
2026-03-08
·
CVE-2026-3009
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A flaw exists in the
IdentityBrokerService.performLogin endpoint of Keycloak that allows authentication to continue using an Identity Provider (IdP) even after it has been administratively disabled. An attacker with knowledge of the IdP alias can reuse a previous login request to circumvent the administrative restriction. This bypasses access control enforcement, potentially enabling unauthorized authentication through a disabled external provider.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak