CVE-2026-3009

Published Mar 5, 2026

Last updated 23 days ago

Overview

Description
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.
Source
secalert@redhat.com
NVD status
Modified
Products
build_of_keycloak, jboss_enterprise_application_platform, jboss_enterprise_application_platform_expansion_pack, single_sign-on

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

secalert@redhat.com
CWE-863
nvd@nist.gov
CWE-863

Social media

Hype score
Not currently trending

Configurations