VYPR
High severity7.7NVD Advisory· Published Mar 18, 2026· Updated Aug 18, 2026

CVE-2026-2092

CVE-2026-2092

Description

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response. This allows the attacker to inject an encrypted assertion for an arbitrary principal, leading to unauthorized access and potential information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.keycloak:keycloak-servicesMaven
<= 26.2.5
org.keycloak:keycloak-servicesMaven
>= 26.3.0, <= 26.4.7
org.keycloak:keycloak-servicesMaven
>= 26.5.0

Affected products

6

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.