{"id":"GHSA-8cr3-vpxx-92cx","summary":"Keycloak SAML Broken has Authentication Bypass by Primary Weakness","details":"A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider (IdP)-initiated broker landing target, it can still complete the login process and establish a Single Sign-On (SSO) session. This allows a remote attacker to gain unauthorized access to other enabled clients without re-authentication, effectively bypassing security restrictions.\n\nA fix is available at https://github.com/keycloak/keycloak/releases/tag/26.5.5.","aliases":["BIT-keycloak-2026-3047","CVE-2026-3047"],"modified":"2026-08-25T12:26:10.825263112Z","published":"2026-03-05T21:30:48Z","database_specific":{"github_reviewed_at":"2026-03-06T22:32:21Z","nvd_published_at":"2026-03-05T19:16:18Z","cwe_ids":["CWE-305"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3047"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3925"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3926"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3947"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3948"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-3047"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2441966"},{"type":"PACKAGE","url":"https://github.com/keycloak/keycloak"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/releases/tag/26.5.5"}],"affected":[{"package":{"name":"org.keycloak:keycloak-broker-saml","ecosystem":"Maven","purl":"pkg:maven/org.keycloak/keycloak-broker-saml"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.8.1.Final"}]}],"versions":["1.2.0.Beta1","1.2.0.CR1","1.2.0.Final","1.3.0.Final","1.3.1.Final","1.4.0.Final","1.5.0-Final","1.5.0.Final","1.5.1.Final","1.6.0.Final","1.6.1.Final","1.7.0.CR1","1.7.0.Final","1.8.0.Alpha1","1.8.0.CR1","1.8.0.CR2","1.8.0.CR3","1.8.0.Final","1.8.1.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8cr3-vpxx-92cx/GHSA-8cr3-vpxx-92cx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}