SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18217

LOW · CVSS 3.4 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

A vulnerability exists in the SAML protocol implementation of Keycloak, where improper handling of authentication requests with wildcard redirect URLs allows attackers to inject malicious parameters. This could result in users being redirected to incorrect accounts, compromising their authentication process. Organizations utilizing Keycloak for identity and access management should prioritize addressing this issue to mitigate potential account takeover risks.

CVE
CVE-2026-18217
Severity
LOW
CVSS
3.4
EPSS
0.19%

Original NVD Description

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.

Related CVEs

Other vulnerabilities affecting the same vendor(s)