A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user. | |
| Title | Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow | |
| First Time appeared |
Redhat
Redhat build Keycloak Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-294 | |
| CPEs | cpe:/a:redhat:build_keycloak: cpe:/a:redhat:jbosseapxp cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-06T05:33:17.868Z
Reserved: 2026-08-05T15:22:29.997Z
Link: CVE-2026-18967
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T07:30:16Z