{"id":"CVE-2026-3009","title":"A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator","summary":"A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-863"],"vendor":"redhat","product":"build_of_keycloak","affected":["build_of_keycloak","build_of_keycloak = 26.4","build_of_keycloak = 26.4.10","jboss_enterprise_application_platform = 8.0","jboss_enterprise_application_platform_expansion_pack","single_sign-on = 7.0"],"patched":["build_of_keycloak 26.4","build_of_keycloak 26.4.10"],"published":"2026-03-05","updated":"2026-09-14","sourceUpdated":"2026-09-14T13:18:31.887","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3009","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:3947","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:3948","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-3009","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2441867","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:3947","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:3948","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-3009","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2441867","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-3009"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3009"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-03-06T18:14:28.750846Z"},"epss":0.00333,"epssPercentile":0.267,"ingestedAt":"2026-08-03T15:26:14.207Z","slug":"CVE-2026-3009","body":"## Overview\n\nA security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.\n\n## Affected\n\n- `build_of_keycloak`\n- `build_of_keycloak = 26.4`\n- `build_of_keycloak = 26.4.10`\n- `jboss_enterprise_application_platform = 8.0`\n- `jboss_enterprise_application_platform_expansion_pack`\n- `single_sign-on = 7.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:3948** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-03-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:3948)\n- **RHSA-2026:3947** · Red Hat · fixed in: Red Hat build of Keycloak 26.4.10 · released 2026-03-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:3947)\n- **Red Hat VEX** · Important · affected: Red Hat Single Sign-On 7 · no fix planned: Red Hat Single Sign-On 7 · updated 2026-09-12 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}