CVE-2026-2092High· 7.7▾ TwilightKeycloak: Unauthorized access via improper validation of encrypted SAML assertions
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
Keycloak's SAML broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response, injecting an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.
org.keycloak:keycloak-services <= 26.2.5org.keycloak:keycloak-services >= 26.3.0, <= 26.4.7org.keycloak:keycloak-services >= 26.5.0, < 26.5.5Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-9795High· 7.3Keycloak has privilege escalation via improper scope mapping enforcement
CVE-2026-2004High· 8.8Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database
CVE-2026-90997High· 7.4A flaw was found in Keycloak
CVE-2025-20327High· 7.7A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input vali…
CVE-2026-75588Low· 2.6Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insec…
CVE-2026-89207Medium· 6.5A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17)