PT-2026-23493 · Red Hat · Keycloak
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A security flaw in the 'IdentityBrokerService.performLogin' endpoint allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass this administrative restriction, undermining access control and potentially allowing unauthorized authentication through a disabled external provider.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak