CVE-2026-3047
Red Hat Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.14, Red Hat build of Keycloak 26.4 취약점
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.
- 대응 우선순위
- 점검
- CVSS
- 8.8
- EPSS
- 0.47% 백분위 38.2% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.03.06