What is CVE-2026-18967?
A vulnerability was discovered in the SAML broker component of Keycloak. When using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions, allowing an attacker to replay a captured valid assertion. Organizations should apply the patch immediately and review their SAML broker configurations.
Azərbaycanca: Keycloak identiklik idarəetmə sisteminin SAML broker komponentində boşluq aşkarlanıb. IdP-Initiated axınında OneTimeUse şərti tətbiq edilmir, bu isə ələ keçirilmiş etibarlı SAML təsdiqinin təkrar istifadəsinə imkan yaradır. Təşkilatlar dərhal yeniləmə tətbiq etməli və SAML konfiqurasiyalarını nəzərdən keçirməlidir.
FAQ2
Which component of Keycloak is affected by CVE-2026-18967?
The vulnerability was discovered in the SAML broker component of Keycloak.
What can an attacker achieve by exploiting CVE-2026-18967?
An attacker can replay a captured valid SAML assertion because Keycloak fails to enforce the OneTimeUse condition in the IdP-Initiated flow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.