GHSA-wmxr-6j5f-838pHigh· 7.7▾ TwilightDuplicate Advisory: Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-794g-x443-36f7. This link is maintained to preserve external references.
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.
org.keycloak:keycloak-saml-adapter-core < 26.2.14org.keycloak:keycloak-saml-core >= 26.3.0, < 26.4.10org.keycloak:keycloak-services >= 26.5.0, < 26.5.5org.keycloak:keycloak-saml-adapter-core >= 26.3.0, < 26.4.10org.keycloak:keycloak-saml-adapter-core >= 26.5.0, < 26.5.5org.keycloak:keycloak-services < 26.2.14org.keycloak:keycloak-services >= 26.3.0, < 26.4.10org.keycloak:keycloak-saml-core < 26.2.14org.keycloak:keycloak-saml-core >= 26.5.0, < 26.5.5Upgrade to a patched release:
org.keycloak:keycloak-saml-adapter-core 26.2.14org.keycloak:keycloak-saml-core 26.4.10org.keycloak:keycloak-services 26.5.5org.keycloak:keycloak-saml-adapter-core 26.4.10org.keycloak:keycloak-saml-adapter-core 26.5.5org.keycloak:keycloak-services 26.2.14org.keycloak:keycloak-services 26.4.10org.keycloak:keycloak-saml-core 26.2.14org.keycloak:keycloak-saml-core 26.5.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-2092High· 7.7A flaw was found in Keycloak
CVE-2026-2004High· 8.8Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database
CVE-2026-9795High· 7.3Keycloak has privilege escalation via improper scope mapping enforcement
CVE-2026-90997High· 7.4A flaw was found in Keycloak
CVE-2026-83557Medium· 5.6DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator
CVE-2025-53627Medium· 5.3Meshtastic is an open source mesh networking solution