Impact
A flaw was discovered in the SAML broker component used by Keycloak to handle identity federation. The IdP‑initiated Single Sign‑On endpoint does not verify whether a provider is configured for link‑only operations. This omission allows an attacker who controls a linked upstream identity to skip the normal login check and acquire full access to the local user account, effectively bypassing authentication. As a consequence the attacker can gain unauthorized access to protected resources and data belonging to that account.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak, the Red Hat Data Grid 8 offering, the JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. Exact impacted versions are not listed in the advisory, so any deployment of these products that includes the SAML broker component is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, while the EPSS score is not available, making it unclear how frequently attackers are exploiting this flaw today. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is remote, requiring the attacker to obtain control of a linked upstream identity and trigger the IdP‑initiated SSO flow. Once the provider restrictions are bypassed, the attacker can log in as the local user and gain full privileges within the affected systems.
OpenCVE Enrichment