CVE-2026-2603Disclosure(redhat / build_of_keycloak)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-18); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
build_of_keycloak

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-09: 1Mentions · 2026-03-11: 1Mentions · 2026-03-18: 4Mentions · 2026-04-17: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-18: 3Technical Details · 2026-04-17: 103-0903-1103-1804-17
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-111
Patch1
2026-03-184
Disclosure2General2
2026-04-171
Disclosure1
Full discourse7 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2603 - High A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-i... https://www.thehackerwire.com/vulnerability/CVE-2026-2603/ https://t.co/iJlS5LXcPs

    Post summary

    The tweet announces a high‑severity flaw in Keycloak that allows control bypass via a valid SAML response from an external IdP, but provides no PoC, exploit, patch, or active exploitation details.

    0001154
    138 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-2603 - Red Hat - Red Hat build of Keycloak 26.2 - https://www.redpacketsecurity.com/cve-alert-cve-2026-2603-red-hat-red-hat-build-of-keycloak-26-2/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2603 #red-hat #red-hat-build-of-keycloak-26-2

    Post summary

    The tweet announces CVE-2026-2603, affecting Red Hat's Keycloak 26.2 build, and links to a detailed alert page, with no additional exploitation, patch, or PoC information.

    0001079
    3.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Keycloak unauthorized authentication via disabled SAML Identity Provider (CVE-2026-2603) could allow illicit access. Review configurations for #Keycloak #SAML #authbypass risks. https://www.pulsepatch.io/posts/cve-2026-2603-keycloak-unauthorized-saml-auth

    Post summary

    The article announces that a misconfiguration in Keycloak's disabled SAML Identity Provider could allow unauthorized authentication, urging administrators to review settings.

    0000048
    12 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-2603 📊 Severity: 8.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2603 #CVE-2026-2603 #CVE #High  #CyberSecurity #InfoSec https://t.co/Hjn7Hd6Zze

    Post summary

    The tweet announces CVE‑2026‑2603 with a severity score of 8.1 and a high risk rating, but it does not provide technical details, PoC, exploit code, or mitigation information.

    0000029
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2603 A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak… https://www.cve.org/CVERecord?id=CVE-2026-2603

    Post summary

    A new Keycloak vulnerability (CVE‑2026‑2603) enables attackers to bypass security controls via a valid SAML response from an external Identity Provider; the text contains technical details of the flaw but no PoC, exploit code, active exploitation, or mitigation.

    00000115
    56.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Keycloak、危険な脆弱性を含む4件を修正(CVE-2026-3047、CVE-2026-3009、CVE-2026-2603、CVE-2026-2092) https://rocket-boys.co.jp/security-measures-lab/keycloak-fixes-4-flaws-including-critical-cve-2026-3047-3009-2603-2092/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The message announces that Keycloak has released patches addressing four critical vulnerabilities identified by the CVE-2026 series.

    00000142
    334 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    Keycloakで4件のSecurity fix CVE-2026-3047 CVE-2026-3009 CVE-2026-2603 CVE-2026-2092 Keycloak 26.5.5 released https://www.keycloak.org/2026/03/keycloak-2655-released

    Post summary

    Keycloak 26.5.5 has been released, addressing four CVEs: CVE-2026-3047, CVE-2026-3009, CVE-2026-2603, and CVE-2026-2092.

    00000475
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---

Explore more