Build Of KeycloakApplication · Redhat

CVE-2026-3047

HIGH · 8.8 CVSS v3.1 Published 2026-03-05
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
94/100
Remediation priority · Urgent
Remotely reachable Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

In Keycloak's SAML broker (org.keycloak.broker.saml), a disabled SAML client configured as an IdP-initiated broker landing target can still complete the authentication flow and establish a valid SSO session. This allows an attacker to bypass the disabled status and gain unauthorized access to other enabled clients without re-authentication, effectively circumventing security controls.

MitigationReview and remove any disabled SAML clients configured as IdP-initiated broker landing targets, or apply available Keycloak security patches. Ensure disabled clients are fully removed from broker configurations rather than merely marked as disabled.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Build Of KeycloakApplication
Affected:all versions= 26.2= 26.2.14= 26.4= 26.4.10
KeycloakApplication
Affected:all versions

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify SAML brokers in your realm
    In Keycloak Admin Console, go to Identity Providers section and look for SAML providers. Alternatively, use the admin API: GET /{realm}/identityProviders/instances to list all identity providers and filter for SAML type.
    Affected if You have SAML-based identity brokers configured in your realm.
  2. Find IdP-initiated broker landing configurations
    Check the SAML identity provider settings for 'Post Broker Login Flow' or 'Trust Email' configuration. Also check realm settings for 'Default Identity Provider' or broker landing page configurations. The specific config path varies by Keycloak version but typically exists in the IdP entity settings.
    Affected if A default identity provider or broker landing target is configured.
  3. List SAML clients used as broker targets
    Review all SAML clients that could serve as IdP-initiated broker landing targets. Use: GET /{realm}/clients to list all clients, filter by protocol=saml, and identify which ones are referenced in broker configurations.
    Affected if SAML clients exist in your realm that could be configured as broker targets.
  4. Check if landing target clients are enabled or disabled
    For each SAML client identified as a broker landing target, check its 'enabled' status via GET /{realm}/clients/{clientUuid} or in the Admin Console under the Client Settings tab.
    Affected if Any SAML client configured as an IdP-initiated broker landing target is currently disabled (enabled=false).
  5. Verify broker endpoint accessibility for disabled clients
    Test whether a disabled SAML client can still establish an SSO session via IdP-initiated broker flow. Initiate SAML authentication from the external IdP targeting the disabled client. If authentication succeeds and a session is created, the vulnerability is present.
    Affected if Authentication succeeds with a disabled SAML client that is configured as an IdP-initiated broker landing target.

Your environment is affected if any disabled SAML client is configured as an IdP-initiated broker landing target and can still complete authentication to establish an SSO session.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

From vendor data
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Review and remove any disabled SAML clients configured as IdP-initiated broker landing targets, or apply available Keycloak security patches. Ensure disabled clients are fully removed from broker configurations rather than merely marked as disabled.

Fix this in Build Of Keycloak Scoped from the published advisory
  • Consultation2.0 h
  • Implementation4.0 h
  • Testing3.0 h
  • Review / QA2.0 h
11.0 hours of engineering $1,930
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,088.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-3047 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-3047 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data