high

CVE-2026-2092

Maven · org.keycloak:keycloak-services • Maven · org.keycloak:keycloak-saml-adapter-core • Maven · org.keycloak:keycloak-saml-core

Summary

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Severity
high
CVSS
7.7
EPSS
0.3% (p23)
CWE
CWE-1287
Also known as
GHSA-794g-x443-36f7, GHSA-wmxr-6j5f-838p#org.keycloak:keycloak-saml-adapter-core, GHSA-wmxr-6j5f-838p#org.keycloak:keycloak-saml-core, GHSA-wmxr-6j5f-838p#org.keycloak:keycloak-services
Published
2026-07-02
Updated
2026-07-02

Advisory details

Keycloak's SAML broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response, injecting an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.