High severity8.1NVD Advisory· Published Mar 5, 2026· Updated Aug 17, 2026
CVE-2026-3009
CVE-2026-3009
Description
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 26.5.5 | 26.5.5 |
Affected products
11- Red Hat/Red Hat build of Keycloak 26.4.10v5cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:jboss_enterprise_application_platform:8+ 1 more
- cpe:/a:redhat:jboss_enterprise_application_platform:8
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0:*:*:*:*:*:*:*
cpe:/a:redhat:jbosseapxp+ 1 more
- cpe:/a:redhat:jbosseapxp
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
cpe:/a:redhat:red_hat_single_sign_on:7+ 1 more
- cpe:/a:redhat:red_hat_single_sign_on:7
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*+ 2 more
- cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:build_of_keycloak:26.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:build_of_keycloak:26.4:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- access.redhat.com/errata/RHSA-2026:3947nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:3948nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2026-3009nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-m297-3jv9-m927ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-3009ghsaADVISORY
- github.com/keycloak/keycloak/commit/4fd5367e6cc28cfa68fb2240fc459c12b1fdbf2aghsaWEB
- github.com/keycloak/keycloak/issues/46911ghsaWEB
- github.com/keycloak/keycloak/releases/tag/26.5.5ghsaWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.jsonnvd
News mentions
0No linked articles in our index yet.