PT-2026-66729 · Red Hat · Keycloak

CVE-2026-18217

·

Published

2026-07-31

·

Updated

2026-08-07

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the SAML protocol implementation when handling authentication requests via the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request containing malicious parameters. Upon user authentication, Keycloak appends the legitimate response to these parameters, resulting in parameter pollution. This may lead some service providers to process the attacker's data instead of the actual login information, potentially causing a user to be logged into an incorrect account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18217

Affected Products

Keycloak