セキュリティ対策Lab[verified]@securityLab_jpPatch
Keycloak has released patches addressing four critical vulnerabilities (CVE-2026-3047, CVE-2026-3009, CVE-2026-2603, CVE-2026-2092), as announced in the linked security update.
CCB Alert@CCBalertPatch
The post alerts to two high‑severity authorization bypass flaws (CVE‑2026‑3047 and CVE‑2026‑3009) in RedHat Keycloak SAML broker, highlights potential remote access risk, and indicates that patches are available.
Autumn Good@autumn_good_35Patch
Keycloak released version 26.5.5, fixing four CVEs: CVE-2026-3047, CVE-2026-3009, CVE-2026-2603, and CVE-2026-2092.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces the discovery of CVE-2026-3009, a Keycloak flaw that allows authentication via a disabled Identity Provider through the IdentityBrokerService.performLogin endpoint.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE‑2026‑3009 as an authentication bypass in Keycloak caused by a disabled identity provider, but provides no PoC, exploit, or remediation details.
CVE@CVEnewDisclosure
A new authentication bypass vulnerability in Keycloak’s IdentityBrokerService.performLogin endpoint (CVE-2026-3009) has been disclosed, with brief technical details but no PoC, exploit, or patch information.