{
  "threat_severity" : "Important",
  "public_date" : "2026-08-05T13:39:33Z",
  "bugzilla" : {
    "description" : "keycloak-services: keycloak-services: SAML broker metadata import disables response signature validation",
    "id" : "2503139",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2503139"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.4",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-347",
  "details" : [ "A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.", "A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier." ],
  "statement" : "The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it allows for unauthenticated account takeover under common configuration scenarios. Successful exploitation allows an attacker to impersonate users and gain full access to their accounts by forging SAML responses. The vulnerability's root cause is an improper configuration of signature validation settings during the SAML IdP metadata import process.",
  "acknowledgement" : "Red Hat would like to thank Paul Bottinelli (Trail of Bits in collaboration with OpenAI) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat build of Keycloak 26.4",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50847",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk/keycloak-operator-bundle:26.4.14-1"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.4",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50847",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk/keycloak-rhel9:26.4-22"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.4",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50847",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk/keycloak-rhel9-operator:26.4-22"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.4.14",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50846",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "keycloak-services"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.4.14",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50846",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.4::el9",
    "package" : "rhbk-openshift-rhel9/rhbk-openshift-rhel9"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50849",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-operator-bundle:26.6.5-1"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50849",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-rhel9:26.6-11"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50849",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk/keycloak-rhel9-operator:26.6-11"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6.5",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50848",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "keycloak-services"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6.5",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50848",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk-keycloak-rhel9/rhbk-keycloak-rhel9"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.6.5",
    "release_date" : "2026-08-05T00:00:00Z",
    "advisory" : "RHSA-2026:50848",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.6::el9",
    "package" : "rhbk-openshift-rhel9/rhbk-openshift-rhel9"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-services",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-16443\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-16443" ],
  "name" : "CVE-2026-16443",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}