{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/red-hat-build-of-keycloak/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-16443"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Red Hat Build of Keycloak"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","saml","identity-management"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-16443 describes a critical security flaw in the SAML metadata import functionality within the keycloak-services component of Red Hat Build of Keycloak. The vulnerability arises when an administrator or automated process imports identity provider metadata that lacks specific usage attributes for keys. Under these conditions, the Keycloak engine incorrectly disables signature validation for subsequent SAML responses, even if a valid signing certificate is present in the metadata. This oversight creates an authentication bypass scenario, as the application fails to verify the integrity and origin of incoming SAML tokens. An unauthenticated attacker, knowing a target user's external identifier, can forge a SAML response, masquerade as a legitimate user, and gain unauthorized access to the affected environment. The flaw poses a significant risk to organizations relying on Keycloak for identity brokering and single sign-on services, as it fundamentally compromises the trust relationship between the service provider and the identity provider.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to user accounts within applications protected by Keycloak. In enterprise environments, this may lead to full account takeover, unauthorized access to sensitive corporate resources, and potential data exfiltration. The vulnerability impacts all deployments of Red Hat Build of Keycloak utilizing SAML identity brokering features that rely on metadata imports.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Red Hat Build of Keycloak to the latest patched version provided by Red Hat to resolve CVE-2026-16443.\u003c/li\u003e\n\u003cli\u003eAudit all configured SAML identity providers in the Keycloak admin console to ensure \u0026quot;Signature Validation\u0026quot; is explicitly enabled and not reliant on default or metadata-derived settings.\u003c/li\u003e\n\u003cli\u003eReview SAML authentication logs for suspicious successful login events where the assertion signature could not be verified or where assertions originated from unexpected identity provider endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T15:20:39Z","date_published":"2026-08-05T15:20:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-keycloak-saml-bypass/","summary":"An authentication bypass vulnerability in Red Hat Build of Keycloak allows unauthenticated attackers to forge SAML assertions by manipulating metadata import settings to disable signature validation.","title":"CVE-2026-16443: Signature Validation Bypass in Keycloak SAML Metadata Import","url":"https://feed.craftedsignal.io/briefs/2026-08-keycloak-saml-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Red Hat Build of Keycloak","version":"https://jsonfeed.org/version/1.1"}