A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An att…
High CVSS 7.7
Summary
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2026:3925 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:3926 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:3947 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:3948 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-2092 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2437296 Issue Tracking
- https://access.redhat.com/errata/RHSA-2026:3925 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:3926 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:3947 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:3948 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-2092 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2437296 Issue Tracking
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2092.json Vendor Advisory
Timeline
- nvd_ingest NVD