⚠ Withdrawn by GitHub Security Advisories

Withdrawn: July 2, 2026

GHSA-wmxr-6j5f-838pHighCVSS 7.7Disclosed before NVD

Duplicate Advisory: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Published
March 18, 2026
Last Modified
July 2, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-794g-x443-36f7. This link is maintained to preserve external references.

Original Description

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

🎯 Affected products9

  • maven/org.keycloak:keycloak-saml-adapter-core:< 26.2.14
  • maven/org.keycloak:keycloak-saml-core:>= 26.3.0, < 26.4.10
  • maven/org.keycloak:keycloak-services:>= 26.5.0, < 26.5.5
  • maven/org.keycloak:keycloak-saml-adapter-core:>= 26.3.0, < 26.4.10
  • maven/org.keycloak:keycloak-saml-adapter-core:>= 26.5.0, < 26.5.5
  • maven/org.keycloak:keycloak-services:< 26.2.14
  • maven/org.keycloak:keycloak-services:>= 26.3.0, < 26.4.10
  • maven/org.keycloak:keycloak-saml-core:< 26.2.14
  • maven/org.keycloak:keycloak-saml-core:>= 26.5.0, < 26.5.5

🔗 References (10)