CVE-2026-3009Disclosure(redhat / build_of_keycloak)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat build_of_keycloak systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • build_of_keycloak
  • jboss_enterprise_application_platform
  • jboss_enterprise_application_platform_expansion_pack
  • single_sign-on

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-06); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
build_of_keycloakjboss_enterprise_application_platformjboss_enterprise_application_platform_expansion_packsingle_sign-on

5 versions affected across 4 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-08: 103-0503-0603-0803-0903-11
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-062
Disclosure1Patch1
2026-03-081
Disclosure1
2026-03-091
Patch1
2026-03-111
Patch1
Full discourse6 posts
  • CCB Alert@CCBalert
    Patch

    Warning: 2 high improper authorization & authentication bypass in #RedHat #Keycloack #SAMLbroker. CVE-2026-3047 CVE-2026-3009 CVSS: 8.8 - 8.1. A remote attacker can gain unauthorized access to the system and bypass sec restrictions due to an access ctrl enforcement error #Patch

    Post summary

    The post alerts to two high‑severity authorization bypass flaws (CVE‑2026‑3047 and CVE‑2026‑3009) in RedHat Keycloak SAML broker, highlights potential remote access risk, and indicates that patches are available.

    02011265
    7.2K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Keycloak、危険な脆弱性を含む4件を修正(CVE-2026-3047、CVE-2026-3009、CVE-2026-2603、CVE-2026-2092) https://rocket-boys.co.jp/security-measures-lab/keycloak-fixes-4-flaws-including-critical-cve-2026-3047-3009-2603-2092/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Keycloak has released patches addressing four critical vulnerabilities (CVE-2026-3047, CVE-2026-3009, CVE-2026-2603, CVE-2026-2092), as announced in the linked security update.

    00000142
    334 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    Keycloakで4件のSecurity fix CVE-2026-3047 CVE-2026-3009 CVE-2026-2603 CVE-2026-2092 Keycloak 26.5.5 released https://www.keycloak.org/2026/03/keycloak-2655-released

    Post summary

    Keycloak released version 26.5.5, fixing four CVEs: CVE-2026-3047, CVE-2026-3009, CVE-2026-2603, and CVE-2026-2092.

    00000475
    6.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3009 - High A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administr... https://www.thehackerwire.com/vulnerability/CVE-2026-3009/ https://t.co/JjQ0DCubDm

    Post summary

    The tweet announces the discovery of CVE-2026-3009, a Keycloak flaw that allows authentication via a disabled Identity Provider through the IdentityBrokerService.performLogin endpoint.

    0000045
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3009 Authentication Bypass via Disabled Identity Provider in Keycloak https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3009 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE‑2026‑3009 as an authentication bypass in Keycloak caused by a disabled identity provider, but provides no PoC, exploit, or remediation details.

    0000067
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3009 A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been … https://www.cve.org/CVERecord?id=CVE-2026-3009

    Post summary

    A new authentication bypass vulnerability in Keycloak’s IdentityBrokerService.performLogin endpoint (CVE-2026-3009) has been disclosed, with brief technical details but no PoC, exploit, or patch information.

    0000099
    56.6K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatbuild_of_keycloak---
Appredhatbuild_of_keycloak26.4--
Appredhatbuild_of_keycloak26.4.10--
Appredhatjboss_enterprise_application_platform8.0--
Appredhatjboss_enterprise_application_platform_expansion_pack---
Appredhatsingle_sign-on7.0--

Explore more