What is CVE-2026-16442?
This CVE identifies a flaw in Keycloak's SAML broker component where the IdP-initiated Single Sign-On endpoint does not verify if a provider is restricted to account linking only. This allows an attacker with control to potentially bypass account linking restrictions. Users are advised to update Keycloak to the latest version immediately.
Azərbaycanca: Bu CVE Keycloak-ın SAML broker komponentində aşkarlanmış boşluqdur. Boşluq İdP-in başlatdığı Single Sign-On endpoint-inin provayderin yalnız hesab bağlantısı ilə məhdudlaşdırıldığını yoxlamaması səbəbilə yaranır. Təcili olaraq Keycloak-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Keycloak
FAQ2
In which component of Keycloak was CVE-2026-16442 discovered?
This flaw was discovered in the SAML broker component of Keycloak.
What is recommended for users to protect against CVE-2026-16442?
Users are advised to update Keycloak to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.