Status: UPDATED
| Advisory ID: CVE-2026-16443
Key Details
| CVE | CVE-2026-16443 |
| CVSS Score / Version | 7.4 (High) / CVSS v3.1 |
| Updated | 2026-09-24 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. |
| Affected products | Red Hat Build of Keycloak |
| Classified as | CWE-347 (Improper Verification of Cryptographic Signature) |
| Exploitation prediction (EPSS) | 0.26% probability of exploitation in the next 30 days (15% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | Core Infrastructure |
| Sectors | Multiple |
What to Know
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
What to Do
Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.
References