CVE-2026-3047
published 2026-03-05CVE-2026-3047: A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.47%
37.6th percentile
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | — | — |
| redhat | build_of_keycloak | — | — |
| redhat | build_of_keycloak | — | — |
| redhat | build_of_keycloak | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for successful SSO session establishment originating from a disabled SAML client configured as an IdP-initiated broker landing target in Keycloak — this indicates authentication bypass exploitation. ↗
- →Monitor Keycloak audit/event logs for login events associated with disabled SAML clients (client_id flagged as disabled in realm config) that nonetheless produce authenticated sessions, especially followed by access to other enabled clients without re-authentication. ↗
- →Audit Keycloak realm configurations for any disabled SAML client set as an IdP-initiated broker landing target; presence of such a configuration is a prerequisite for exploitation. ↗
- →Focus detection on the org.keycloak.broker.saml component (artifact: org.keycloak:keycloak-broker-saml); flag deployments running unpatched versions of this library. ↗
- ·Exploitation requires a specific misconfiguration: a disabled SAML client must be explicitly set as the IdP-initiated broker landing target in the Keycloak realm. Environments without this configuration are not directly vulnerable. ↗
- ·Mitigation (prior to patching) is to remove disabled SAML clients from IdP-initiated broker landing target configurations in all Keycloak realm settings. ↗
- ·No fix was available at initial publication (March 5, 2026); a fix was added to the Maven package org.keycloak:keycloak-broker-saml on March 8, 2026. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.keycloak.broker.saml: Keycloak SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login
vendor_redhat·2026-03-05·CVSS 8.8
CVE-2026-3047 [HIGH] CWE-305 org.keycloak.broker.saml: Keycloak SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login
org.keycloak.broker.saml: Keycloak SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establis
GHSA
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
ghsa·2026-03-05
CVE-2026-3047 [HIGH] CWE-305 Keycloak SAML Broken has Authentication Bypass by Primary Weakness
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
A fix is available at https://github.com/keycloak/keycloak/releases/tag/26.5.5.
OSV
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
osv·2026-03-05
CVE-2026-3047 [HIGH] Keycloak SAML Broken has Authentication Bypass by Primary Weakness
Keycloak SAML Broken has Authentication Bypass by Primary Weakness
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
A fix is available at https://github.com/keycloak/keycloak/releases/tag/26.5.5.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:3925https://access.redhat.com/errata/RHSA-2026:3926https://access.redhat.com/errata/RHSA-2026:3947https://access.redhat.com/errata/RHSA-2026:3948https://access.redhat.com/security/cve/CVE-2026-3047https://bugzilla.redhat.com/show_bug.cgi?id=2441966https://access.redhat.com/errata/RHSA-2026:3925https://access.redhat.com/errata/RHSA-2026:3926https://access.redhat.com/errata/RHSA-2026:3947https://access.redhat.com/errata/RHSA-2026:3948https://access.redhat.com/security/cve/CVE-2026-3047https://bugzilla.redhat.com/show_bug.cgi?id=2441966https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3047.json
2026-03-05
Published