CVE-2026-2092Disclosure(redhat / build_of_keycloak)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-18); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
build_of_keycloak

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-03-09: 1Mentions · 2026-03-11: 1Mentions · 2026-03-18: 4Mentions · 2026-04-09: 1Mentions · 2026-06-02: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-03-18: 2Technical Details · 2026-04-09: 1Technical Details · 2026-06-02: 103-0903-1103-1804-0906-02
Signal classification3 categories
Disclosure
337.5%
General
337.5%
Patch
225.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-091
Patch1
2026-03-111
Patch1
2026-03-184
Disclosure2General2
2026-04-091
General1
2026-06-021
Disclosure1
Full discourse8 posts
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-2092 Keycloak: Unauthorized access via improper validation of encrypted SAML assertions https://github.com/keycloak/keycloak/security/advisories/GHSA-794g-x443-36f7

    Post summary

    The advisory announces a Keycloak vulnerability that allows unauthorized access due to improper SAML assertion validation, but no proof‑of‑concept, exploit, or mitigation details are provided.

    01021497
    6.9K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-2092 - Red Hat - Red Hat build of Keycloak 26.2 - https://www.redpacketsecurity.com/cve-alert-cve-2026-2092-red-hat-red-hat-build-of-keycloak-26-2/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2092 #red-hat #red-hat-build-of-keycloak-26-2

    Post summary

    A brief CVE alert announcing CVE‑2026‑2092 affecting Red Hat’s Keycloak 26.2 build, linking to a website for further details.

    0000178
    3.6K followersView on X
  • PulsePatch.io@pulsepatchio
    General

    Unauthorized access via improper validation of encrypted SAML assertions affects `Keycloak` (CVE-2026-2092). Monitor official channels for patch availability. #Keycloak #SAML #AuthBypass https://www.pulsepatch.io/posts/cve-2026-2092-keycloak-saml-auth-bypass

    Post summary

    The tweet reports that Keycloak CVE‑2026‑2092 enables unauthorized access via improper validation of encrypted SAML assertions and advises users to monitor for an upcoming patch, with no PoC, exploit, or active exploitation mentioned.

    0000044
    11 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-2092 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2092 #CVE-2026-2092 #CVE #High  #CyberSecurity #InfoSec https://t.co/rq02q5431D

    Post summary

    The tweet provides a brief alert and a link to the NVD entry, but lacks any technical detail, exploitation evidence, or remediation guidance.

    0000034
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2092 A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML… https://www.cve.org/CVERecord?id=CVE-2026-2092

    Post summary

    Keycloak's SAML broker endpoint fails to properly validate encrypted assertions, indicating a potential security vulnerability.

    00000116
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-2092 SAML Assertion Injection Vulnerability in Keycloak Authentication ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2092 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    CVE-2026-2092 is described as a SAML assertion injection flaw in Keycloak Authentication, yet the post offers no PoC, exploit details, patch information, or evidence of active exploitation.

    0000043
    4.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Keycloak、危険な脆弱性を含む4件を修正(CVE-2026-3047、CVE-2026-3009、CVE-2026-2603、CVE-2026-2092) https://rocket-boys.co.jp/security-measures-lab/keycloak-fixes-4-flaws-including-critical-cve-2026-3047-3009-2603-2092/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces that Keycloak has released patches for four CVEs, including a critical one, with no mention of proof of concept, exploit, or active attacks.

    00000142
    334 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    Keycloakで4件のSecurity fix CVE-2026-3047 CVE-2026-3009 CVE-2026-2603 CVE-2026-2092 Keycloak 26.5.5 released https://www.keycloak.org/2026/03/keycloak-2655-released

    Post summary

    Keycloak released version 26.5.5, which contains security fixes for four CVEs.

    00000475
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more