Feed/CVE-2026-2092
CVE-2026-2092HIGHCVSS 7.7

Keycloak: Unauthorized access via improper validation of encrypted SAML assertions

Published Jul 2, 2026·Updated Aug 18, 2026

NVD Description

Keycloak's SAML broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response, injecting an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

Affected Packages (1)

org.keycloak:keycloak-servicesMAVEN
Fixed in = 26.2.5

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free