CVE-2026-2603 PUBLISHED CVSS 8.100000381469727 HIGH

Keycloak: Unauthorized authentication via disabled SAML Identity Provider

EPSS 0.17% · 38.4th percentile

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.17%
38.4th percentile

Affected Products

VendorProductVersions
Red HatRed Hat build of Keycloak 26.2.14
Red HatRed Hat build of Keycloak 26.226.2.14-1, 26.2.14-1, 26.2.14-1
Red HatRed Hat build of Keycloak 26.426.4-12, 26.4-12, 26.4-12
Red HatRed Hat build of Keycloak 26.226.2-16, 26.2-16, 26.2-16
Red HatRed Hat build of Keycloak 26.426.4-12, 26.4-12, 26.4-12
Red HatRed Hat build of Keycloak 26.226.2-16, 26.2-16, 26.2-16
Mavenorg.keycloak:keycloak-server-spi-private0, 0, 0
Red HatRed Hat build of Keycloak 26.4.10
Mavenorg.keycloak:keycloak-services0, 0, 0
Red HatRed Hat build of Keycloak 26.426.4.10-1, 26.4.10-1, 26.4.10-1

Timeline

References

Open in Interactive Console →