Red Hat Security Advisory: Red Hat build of Keycloak 26.2.14 Images Update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-2092 — keycloak-services: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions CVE-2026-2603 — keycloak: Keycloak: Unauthorized authentication via disabled SAML Identity Provider CVE-2026-3047 — org.keycloak.broker.saml: Keycloak SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login
🎯 Affected products10
- Red Hat build of Keycloak 26.2
- rhbk/keycloak-operator-bundle@sha256:ca0959572305bc27cc969355f06e14b0bb5c7dedea9619e884f7bd3bec9bb2bc_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:252532cad9e091df87b895d82a59dfb6bc7bc97a777fe313ca43f0cacee7bd10_arm64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:6dead5fff17a33fc1e37a28f98051f631a74b616d0a2d66fe84169d0eeaed0b4_ppc64le as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:c1664981fec90044019cc72cd634f7d1568e9ca906bce2c6365dfa548ac88122_amd64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9-operator@sha256:cb02cd23c13e0ae1e6404784b22608444b0752749432970ad1e8c4f2cd74ea53_s390x as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:08b5b94d827dbdaba29126c9389476341d1ca9ebeca6a764491862a38d19bb0e_s390x as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:172d9f060709fdf5df5b6a8db9dc8001ff4d41025900e225d43ded8d189522d6_ppc64le as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:708b0282101911143c468a7c78a3c815e8a8fcee01d001d1e9504d7fa14c9337_arm64 as a component of Red Hat build of Keycloak 26.2
- rhbk/keycloak-rhel9@sha256:97f579e9720a458a3d4a277dd19cc0e669b70bf863fdda5298f420d6442dd199_amd64 as a component of Red Hat build of Keycloak 26.2
✅ Remediation
Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, ensure that any SAML client intended to be disabled is not configured as an IdP-initiated broker landing target within Keycloak. Review your Keycloak realm configurations to identify and remove any such associations for disabled clients.