Skip to content
Red HatCVE-2026-18967

Red Hat SAML broker: capture-replay

Medium6.4CVE-2026-18967 · Published Aug 6, 2026 · updated Aug 10, 2026

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Build of Keycloak
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform Expansion Pack
Product
all versionsNo fix yet
Red Hat Single Sign-On 7
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-294

More Red Hat advisories

All Red Hat
Advisory
Red Hat udisks2: privilege escalation
High7.8Aug 6
Red Hat GStreamer gst-plugins-good: denial of service
High7.5Aug 6
Red Hat Enterprise Linux 10: integer overflow
Low2.2Aug 5
Red Hat RPM: buffer overflow
Medium5.5Aug 5
Red Hat OpenShift Container Platform 4: authentication bypass
Medium6.5Aug 5
Red Hat SAML broker: origin validation error
High7.4Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.