← All Advisories

Red Hat Build of Keycloak Cryptographic Signature Verification Flaw Scores 7.4

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-16443

Key Details

CVECVE-2026-16443
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsRed Hat Build of Keycloak
Classified asCWE-347 (Improper Verification of Cryptographic Signature)
Exploitation prediction (EPSS)0.26% probability of exploitation in the next 30 days (15% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatBuild of Keycloak
SubsystemsCore Infrastructure
SectorsMultiple

What to Know

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-16443
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-16443
Vendor advisoryhttps://access.redhat.com/errata/RHSA-2026:50846