Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16443— Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation

CVSS 7.4 · High

Possible ATT&CK Techniques 1AI

T1078 · Valid Accounts

Affected Version Matrix 14

VendorProductVersion RangeStatus
Red HatRed Hat build of Keycloak 26.426.4.14-1< *unaffected
26.4-22< *unaffected
26.4-22< *unaffected
Red HatRed Hat build of Keycloak 26.4.14anyunaffected
anyunaffected
Red HatRed Hat build of Keycloak 26.626.6.5-1< *unaffected
26.6-11< *unaffected
26.6-11< *unaffected
Red HatRed Hat build of Keycloak 26.6.5anyunaffected
anyunaffected
anyunaffected
Red HatRed Hat Data Grid 8anyunaffected
Red HatRed Hat JBoss Enterprise Application Platform Expansion Packanyunaffected
Red HatRed Hat Single Sign-On 7anyunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-16443

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat build of Keycloak 26.4 26.4.14-1 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4 26.4-22 ~ * cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4.14-cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.4.14-cpe:/a:redhat:build_keycloak:26.4::el9
Red HatRed Hat build of Keycloak 26.6 26.6.5-1 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6 26.6-11 ~ * cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.5-cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.5-cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat build of Keycloak 26.6.5-cpe:/a:redhat:build_keycloak:26.6::el9
Red HatRed Hat Data Grid 8-cpe:/a:redhat:jboss_data_grid:8
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack-cpe:/a:redhat:jbosseapxp
Red HatRed Hat Single Sign-On 7-cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-16443

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16443

登录查看更多情报信息。

Vendor Advisories for CVE-2026-16443 (4)

Other References for CVE-2026-16443 (2)

Same Patch Batch · Red Hat · 2026-08-05 · 14 CVEs total

CVE-2026-100909.9 CRITICALMulticluster-operators-subscription: multicluster-operators-subscription: namespace edit u
CVE-2026-100599.1 CRITICALCluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cl
CVE-2026-155728.8 HIGHKeycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows p
CVE-2026-161028.1 HIGHKeycloak-services: keycloak-services: default dcr policy allows role forgery via user prop
CVE-2026-155738.1 HIGHKeycloak-services: keycloak-services: authorization bypass via unnormalized uri matching i
CVE-2026-164427.4 HIGHKeycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only r
CVE-2026-712267.3 HIGHLibkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot ai
CVE-2026-493316.5 MEDIUMOpenshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on
CVE-2026-161006.5 MEDIUMKeycloak-services: keycloak-services: unbounded metric cardinality in user event metrics v
CVE-2026-712256.5 MEDIUMLibkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state rese
CVE-2026-446055.5 MEDIUMRpm: heap buffer overflow in ndb slot table parsing
CVE-2026-160715.4 MEDIUMKeycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users
CVE-2026-712275.1 MEDIUMLibkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandl

IV. Related Vulnerabilities

V. Comments for CVE-2026-16443

No comments yet


Leave a comment