Description
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Published: 2026-08-05
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs in the SAML metadata import function of Keycloak services used for identity brokering. When an identity provider’s metadata lacks the appropriate key‑usage attributes, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This flaw is a CWE‑347 Missing Parameter Value vulnerability that permits an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account that is identified by an external identifier known to the attacker.

Affected Systems

Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Data Grid 8 are affected. Version information is not specified in the current advisory.

Risk and Exploitability

A CVSS score of 7.4 indicates high severity; the EPSS score is not available and the vulnerability is not listed in CISA KEV. The flaw requires no authentication to exploit but it does require that an attacker can influence the import of SAML metadata—typically through privileged access to the broker configuration or by hosting a malicious metadata document. Once the vulnerability is triggered the attacker can create forged SAML responses that the system accepts, enabling unauthorized login to user accounts when the attacker knows the target’s external identifier.

Generated by OpenCVE AI on August 5, 2026 at 16:05 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Enforce that only trusted metadata sources are imported and validate that key‑usage attributes are present before accepting an identity provider’s metadata.
  • Configure the SAML broker to require signature validation regardless of metadata contents; never allow the broker to disable validation automatically.
  • Implement continuous monitoring of SAML authentication logs for anomalous or unexpected login patterns that could indicate forged responses.
  • Official workaround: No effective mitigation options are available; the options that exist do not meet Red Hat Product Security criteria.

Generated by OpenCVE AI on August 5, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on
Vendors & Products Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign-on

Thu, 06 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 05 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak: cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
References

Wed, 05 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Title Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
Weaknesses CWE-347
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid 8 Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-05T18:12:25.454Z

Reserved: 2026-07-21T07:41:14.816Z

Link: CVE-2026-16443

cve-icon Vulnrichment

Updated: 2026-08-05T14:35:32.145Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T14:17:03.697

Modified: 2026-08-10T18:52:14.427

Link: CVE-2026-16443

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-05T13:39:33Z

Links: CVE-2026-16443 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:30:11Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature