---
schema: 1
kind: vulnerability
title: "CVE-2026-16443 — Keycloak: importing SAML metadata without key-usage attributes silently disables response signature validation, so an unauthenticated attacker forges a login as any known user"
headline: "Keycloak's identity broker stopped checking SAML signatures on a metadata-import edge case — one of seven CVEs fixed in 26.4.14 / 26.6.5 / 26.7.1"
summary: >
  Seven Keycloak CVEs were disclosed on 2026-08-05 in keycloak-services, the identity-brokering engine
  behind Keycloak and Red Hat Build of Keycloak, and relayed to European constituents by CERT-FR on 2026-08-06. In CVE-2026-16443 (CVSS 7.4), importing an identity
  provider's SAML metadata that lacks explicit key-usage attributes makes Keycloak disable SAML response
  signature validation even though a signing certificate was supplied — letting an unauthenticated attacker
  forge a SAML response and log in as any user whose external identifier they know. Two Dynamic Client
  Registration flaws (CVE-2026-15572 at 8.8, CVE-2026-16102 at 8.1) reach full realm-administrator control.
  Affected: Keycloak before 26.4.14, 26.6.x before 26.6.5, 26.7.x before 26.7.1. No exploitation reported.
discovered_at: "2026-08-07T04:41:00Z"
event_date: "2026-08-05"
run_id: 2026-08-07T0411Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, identity, auth-bypass, priv-esc, pre-auth, patch-available]
regions: [europe, switzerland, global]
sectors: [public-sector, finance, healthcare]
entities: []
techniques: [T1190, T1556, T1078.004, T1068, T1606.002, T1499.004]
affected_products: ["Keycloak", "Red Hat Build of Keycloak"]
cves:
  - id: CVE-2026-16443
    cvss: "7.4"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "< 26.4.14; 26.6.x < 26.6.5; 26.7.x < 26.7.1"
    fixed: "26.4.14 / 26.6.5 / 26.7.1"
  - id: CVE-2026-16442
    cvss: "7.4"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "< 26.4.14; 26.6.x < 26.6.5; 26.7.x < 26.7.1"
    fixed: "26.4.14 / 26.6.5 / 26.7.1"
  - id: CVE-2026-15572
    cvss: "8.8"
    epss: null
    type: priv-esc
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "< 26.4.14; 26.6.x < 26.6.5; 26.7.x < 26.7.1"
    fixed: "26.4.14 / 26.6.5 / 26.7.1"
  - id: CVE-2026-16102
    cvss: "8.1"
    epss: null
    type: priv-esc
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "< 26.4.14; 26.6.x < 26.6.5; 26.7.x < 26.7.1"
    fixed: "26.4.14 / 26.6.5 / 26.7.1"
  - id: CVE-2026-15573
    cvss: "8.1"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "< 26.4.14; 26.6.x < 26.6.5; 26.7.x < 26.7.1"
    fixed: "26.4.14 / 26.6.5 / 26.7.1"
  - id: CVE-2026-16071
    cvss: "5.4"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: admin-required
    status: [patch-available]
    affected: "< 26.4.14; 26.6.x < 26.6.5; 26.7.x < 26.7.1"
    fixed: "26.4.14 / 26.6.5 / 26.7.1"
  - id: CVE-2026-16100
    cvss: "6.5"
    epss: null
    type: dos
    vector: zero-click
    auth: post-auth
    status: [patch-available]
    affected: "< 26.4.14; 26.6.x < 26.6.5; 26.7.x < 26.7.1"
    fixed: "26.4.14 / 26.6.5 / 26.7.1"
sources:
  - url: "https://access.redhat.com/security/cve/CVE-2026-16443"
    publisher: "Red Hat Product Security"
    date: "2026-08-05"
    role: primary
  - url: "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0976/"
    publisher: "CERT-FR (ANSSI)"
    date: "2026-08-06"
    role: primary
  - url: "https://access.redhat.com/security/cve/CVE-2026-15572"
    publisher: "Red Hat Product Security"
    date: "2026-08-05"
    role: corroborating
  - url: "https://access.redhat.com/security/cve/CVE-2026-16102"
    publisher: "Red Hat Product Security"
    date: "2026-08-05"
    role: corroborating
closed_sources: []
evidence:
  - quote: "This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier."
    publisher: "Red Hat Product Security"
  - quote: "Keycloak versions 26.6.x antérieures à 26.6.5"
    publisher: "CERT-FR (ANSSI)"
verification: multi-source
sourcing_note: >
  Per-CVE scores and mechanics are transcribed from Red Hat's own CVE records for each identifier — the
  vendor authority for Keycloak and Red Hat Build of Keycloak — rather than from the multi-CVE CERT-FR
  bulletin, which carries the advisory and the affected-version boundaries but not per-flaw scoring.
  Keycloak's upstream GitHub Security Advisories could not be read directly (github.com is unreachable
  from this environment); Red Hat's records were used as the first-party substitute and CERT-FR
  independently corroborates the version ranges.
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Upgrade Keycloak to 26.4.14, 26.6.5 or 26.7.1 (or the matching Red Hat Build of Keycloak release), then verify on each configured SAML identity provider that response signature validation is enabled — the flaw is that an import silently disabled it, so confirm the post-upgrade state on providers imported earlier rather than assuming the upgrade restored it."
  - "Review Dynamic Client Registration-created clients for protocol mappers that hardcode realm-admin or client-admin roles, and restrict Initial Access Token issuance to the registrations that need it."
migrated_from: null
---

Keycloak's SAML identity-brokering path stopped enforcing the one guarantee that makes federated login trustworthy. In CVE-2026-16443, when Keycloak imports an upstream identity provider's SAML metadata that lacks specific usage attributes for its keys, it disables signature validation for SAML responses even though a signing certificate was supplied — and Red Hat's own record states the consequence plainly: "This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier" ([Red Hat Product Security, 2026-08-05](https://access.redhat.com/security/cve/CVE-2026-16443)). The external identifier is not a secret — it is typically a username or email address as the upstream IdP renders it — so the practical precondition is knowing who you want to be. Red Hat rates the flaw Important at CVSS 7.4, with the score held down by attack complexity rather than by any authentication requirement (`AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N`).

A sibling flaw in the same broker, CVE-2026-16442 (also CVSS 7.4), lets the IdP-initiated single-sign-on endpoint skip the check for whether a provider is restricted to account linking only, so an attacker controlling a linked upstream identity bypasses that restriction and reaches full access to the local account ([Red Hat Product Security, 2026-08-05](https://access.redhat.com/security/cve/CVE-2026-16442)). The two Dynamic Client Registration flaws are the privilege-escalation half of the batch: CVE-2026-15572 (CVSS 8.8) exploits the "Allowed Protocol Mapper Types" policy failing to re-validate a mapper's *type* on client update when its configuration is unchanged, so an attacker registers a permitted mapper and then swaps it for a restricted one that hardcodes administrative roles ([Red Hat Product Security, 2026-08-05](https://access.redhat.com/security/cve/CVE-2026-15572)); CVE-2026-16102 (CVSS 8.1) abuses the default DCR policy's mis-validated claim path for User Property mappers to write into sensitive internal claim locations and forge administrative roles into the attacker's own access token, which Red Hat says "allows the attacker to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm" ([Red Hat Product Security, 2026-08-05](https://access.redhat.com/security/cve/CVE-2026-16102)). The remaining three are CVE-2026-15573 (CVSS 8.1), where PathMatcher compares request paths to authorization policies without normalising the URI, so a trailing slash or a matrix parameter selects a weaker policy; CVE-2026-16071 (CVSS 5.4), where a delegated administrator's LDAP entry-DN search escapes the configured users-DN boundary and imports directory entries from outside it; and CVE-2026-16100 (CVSS 6.5), where raw error text from failed account operations becomes an unbounded Prometheus metric label and exhausts memory.

CERT-FR carried the batch to European constituents on 2026-08-06, a day after disclosure, and records the affected range as Keycloak before 26.4.14, 26.6.x before 26.6.5, and 26.7.x before 26.7.1 ([CERT-FR, 2026-08-06](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0976/)). No party reports exploitation or public exploit code. The reason this batch matters more than its scores suggest is placement: Keycloak is the identity broker in front of a large share of European public-sector federated-login and e-government portal estates, so a forged assertion is not one application's problem but every application behind that realm. Detection concepts, telemetry class first: in identity-provider audit records, a forged SAML response has no counterpart in the upstream IdP's own authentication log, so correlating broker-login successes against the upstream provider's sign-in events for the same principal and interval surfaces assertions nobody upstream issued; and because Dynamic Client Registration happens over the registration API rather than the admin console, mapper or claim-path changes on DCR-managed clients that carry no matching administrative session are the signal for the privilege-escalation pair. **Triage:** routine Keycloak upgrades and scheduled IdP metadata refreshes both touch these same code paths, so the discriminator is not the configuration change itself but its provenance — a broker-login success with no upstream authentication behind it, or a protocol-mapper type that changed on a client no administrator touched.
