---
id: GHSA-wmxr-6j5f-838p
title: >-
  Duplicate Advisory: Keycloak: Unauthorized access via improper validation of
  encrypted SAML assertions
summary: >-
  Duplicate Advisory: Keycloak: Unauthorized access via improper validation of
  encrypted SAML assertions
severity: high
cvss: 7.7
cwe:
  - CWE-1287
vendor: keycloak
product: 'org.keycloak:keycloak-saml-adapter-core'
ecosystem: maven
affected:
  - 'org.keycloak:keycloak-saml-adapter-core < 26.2.14'
  - 'org.keycloak:keycloak-saml-core >= 26.3.0, < 26.4.10'
  - 'org.keycloak:keycloak-services >= 26.5.0, < 26.5.5'
  - 'org.keycloak:keycloak-saml-adapter-core >= 26.3.0, < 26.4.10'
  - 'org.keycloak:keycloak-saml-adapter-core >= 26.5.0, < 26.5.5'
  - 'org.keycloak:keycloak-services < 26.2.14'
  - 'org.keycloak:keycloak-services >= 26.3.0, < 26.4.10'
  - 'org.keycloak:keycloak-saml-core < 26.2.14'
  - 'org.keycloak:keycloak-saml-core >= 26.5.0, < 26.5.5'
patched:
  - 'org.keycloak:keycloak-saml-adapter-core 26.2.14'
  - 'org.keycloak:keycloak-saml-core 26.4.10'
  - 'org.keycloak:keycloak-services 26.5.5'
  - 'org.keycloak:keycloak-saml-adapter-core 26.4.10'
  - 'org.keycloak:keycloak-saml-adapter-core 26.5.5'
  - 'org.keycloak:keycloak-services 26.2.14'
  - 'org.keycloak:keycloak-services 26.4.10'
  - 'org.keycloak:keycloak-saml-core 26.2.14'
  - 'org.keycloak:keycloak-saml-core 26.5.5'
published: '2026-03-18'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T00:32:49Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-wmxr-6j5f-838p'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2092'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3925'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3926'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3947'
  - url: 'https://access.redhat.com/errata/RHSA-2026:3948'
  - url: 'https://access.redhat.com/security/cve/CVE-2026-2092'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2437296'
  - url: >-
      https://github.com/keycloak/keycloak/commit/b40a25908d937bb0563ea516487bc2c7c1d92508
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2092.json
  - url: 'https://access.redhat.com/errata/RHSA-2026:76132'
  - url: 'https://access.redhat.com/errata/RHSA-2026:76134'
  - url: 'https://github.com/advisories/GHSA-wmxr-6j5f-838p'
tags:
  - ghsa
  - maven
ingestedAt: '2026-10-06T00:37:36.236Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-794g-x443-36f7. This link is maintained to preserve external references.

### Original Description
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

## Affected packages

- `org.keycloak:keycloak-saml-adapter-core < 26.2.14`
- `org.keycloak:keycloak-saml-core >= 26.3.0, < 26.4.10`
- `org.keycloak:keycloak-services >= 26.5.0, < 26.5.5`
- `org.keycloak:keycloak-saml-adapter-core >= 26.3.0, < 26.4.10`
- `org.keycloak:keycloak-saml-adapter-core >= 26.5.0, < 26.5.5`
- `org.keycloak:keycloak-services < 26.2.14`
- `org.keycloak:keycloak-services >= 26.3.0, < 26.4.10`
- `org.keycloak:keycloak-saml-core < 26.2.14`
- `org.keycloak:keycloak-saml-core >= 26.5.0, < 26.5.5`

## Remediation

Upgrade to a patched release:

- `org.keycloak:keycloak-saml-adapter-core 26.2.14`
- `org.keycloak:keycloak-saml-core 26.4.10`
- `org.keycloak:keycloak-services 26.5.5`
- `org.keycloak:keycloak-saml-adapter-core 26.4.10`
- `org.keycloak:keycloak-saml-adapter-core 26.5.5`
- `org.keycloak:keycloak-services 26.2.14`
- `org.keycloak:keycloak-services 26.4.10`
- `org.keycloak:keycloak-saml-core 26.2.14`
- `org.keycloak:keycloak-saml-core 26.5.5`
