RHSA-2026:3926HighCVSS 8.8

Red Hat Security Advisory: Red Hat build of Keycloak 26.2.14 Update

Published
March 5, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-2092 — keycloak-services: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions CVE-2026-2603 — keycloak: Keycloak: Unauthorized authentication via disabled SAML Identity Provider CVE-2026-3047 — org.keycloak.broker.saml: Keycloak SAML broker: Authentication bypass due to disabled SAML client completing IdP-initiated login

🎯 Affected products1

  • Red Hat build of Keycloak 26.2.14

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, ensure that any SAML client intended to be disabled is not configured as an IdP-initiated broker landing target within Keycloak. Review your Keycloak realm configurations to identify and remove any such associations for disabled clients.

🔗 References (3)