---
id: CVE-2026-3009
title: >-
  A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak
  allows authentication to proceed using an Identity Provider (IdP) even after
  it has been disabled by an administrator
summary: >-
  A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak
  allows authentication to proceed using an Identity Provider (IdP) even after
  it has been disabled by an administrator. An attacker who knows the IdP alias
  can…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-863
vendor: redhat
product: build_of_keycloak
affected:
  - build_of_keycloak
  - build_of_keycloak = 26.4
  - build_of_keycloak = 26.4.10
  - jboss_enterprise_application_platform = 8.0
  - jboss_enterprise_application_platform_expansion_pack
  - single_sign-on = 7.0
patched:
  - build_of_keycloak 26.4
  - build_of_keycloak 26.4.10
published: '2026-03-05'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T13:18:31.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3009'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:3947'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:3948'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-3009'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2441867'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:3947'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:3948'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-3009'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2441867'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-3009'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3009'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-06T18:14:28.750846Z'
epss: 0.0047
epssPercentile: 0.37948
ingestedAt: '2026-08-03T15:26:14.207Z'
---

## Overview

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.

## Affected

- `build_of_keycloak`
- `build_of_keycloak = 26.4`
- `build_of_keycloak = 26.4.10`
- `jboss_enterprise_application_platform = 8.0`
- `jboss_enterprise_application_platform_expansion_pack`
- `single_sign-on = 7.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:3948** · Red Hat · fixed in: Red Hat build of Keycloak 26.4 · released 2026-03-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:3948)
- **RHSA-2026:3947** · Red Hat · fixed in: Red Hat build of Keycloak 26.4.10 · released 2026-03-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:3947)
- **Red Hat VEX** · Important · affected: Red Hat Single Sign-On 7 · no fix planned: Red Hat Single Sign-On 7 · updated 2026-09-12 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.json)
