cbcvebase.
CVE-2026-3047
published 2026-03-05

CVE-2026-3047: A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.47%
37.6th percentile
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.

Affected

4 ranges
VendorProductVersion rangeFixed in
redhatbuild_of_keycloak
redhatbuild_of_keycloak
redhatbuild_of_keycloak
redhatbuild_of_keycloak

Detection & IOCsextracted from sources · hover to see the quote

  • Look for successful SSO session establishment originating from a disabled SAML client configured as an IdP-initiated broker landing target in Keycloak — this indicates authentication bypass exploitation.
  • Monitor Keycloak audit/event logs for login events associated with disabled SAML clients (client_id flagged as disabled in realm config) that nonetheless produce authenticated sessions, especially followed by access to other enabled clients without re-authentication.
  • Audit Keycloak realm configurations for any disabled SAML client set as an IdP-initiated broker landing target; presence of such a configuration is a prerequisite for exploitation.
  • Focus detection on the org.keycloak.broker.saml component (artifact: org.keycloak:keycloak-broker-saml); flag deployments running unpatched versions of this library.
  • ·Exploitation requires a specific misconfiguration: a disabled SAML client must be explicitly set as the IdP-initiated broker landing target in the Keycloak realm. Environments without this configuration are not directly vulnerable.
  • ·Mitigation (prior to patching) is to remove disabled SAML clients from IdP-initiated broker landing target configurations in all Keycloak realm settings.
  • ·No fix was available at initial publication (March 5, 2026); a fix was added to the Maven package org.keycloak:keycloak-broker-saml on March 8, 2026.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.