CVE-2026-16442: Red Hat Build Of Keycloak

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

Affected products

  • Red Hat Build Of Keycloak: from 26.4, before 26.4.14 (fixed in 26.4.14); from 26.6, before 26.6.5 (fixed in 26.6.5)

Published 2026-08-05. Last modified 2026-08-10.