CVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When im
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-16443
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16443 | coverage & exploitation status | NVD · CVE.org |
More from NVD Recent CVEs
- highCVE-2026-7529: The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unau…2026-08-05
- mediumCVE-2026-7456: The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to …2026-08-05
- highCVE-2026-67623: Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attacker…2026-08-05
- highCVE-2026-17506: The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi…2026-08-05
- highCVE-2026-15979: The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulner…2026-08-05