High severity7.4NVD Advisory· Published Aug 5, 2026· Updated Aug 10, 2026
CVE-2026-16443
CVE-2026-16443
Description
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
6- access.redhat.com/errata/RHSA-2026:50846nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:50847nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:50848nvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:50849nvdVendor Advisory
- access.redhat.com/security/cve/CVE-2026-16443nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
1- Keycloak Services: Five Vulnerabilities Including High-Severity Flaws Disclosed TogetherVypr Intelligence · Aug 6, 2026