CVE-2026-16443
Last modified
CVE-2026-16443 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Build Of Keycloak | >= 26.4, < 26.4.14 |
| Redhat | Build Of Keycloak | >= 26.6, < 26.6.5 |
References
- https://access.redhat.com/errata/RHSA-2026:50846Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50847Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50848Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:50849Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-16443Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2503139Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-16443?
How severe is CVE-2026-16443?
How do I fix CVE-2026-16443?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16435IBM WebSphere Application Server 9.0, and 8.5 is affected by…5.9
- CVE-2026-16439In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trac…9.1
- CVE-2026-1644The WP Frontend Profile plugin for WordPress is vulnerable t…4.3
- CVE-2026-16440In Eclipse OpenJ9 versions up to 0.60, a crafted .class file…5.7
- CVE-2026-16441In Eclipse OpenJ9 versions up to 0.60, when executing class …9.6
- CVE-2026-16442A flaw was found in the SAML broker component of Keycloak, w…9.8
- CVE-2026-16444Improper neutralization of path traversal sequences in TeamV…7.5
- CVE-2026-16445A flaw was found in dracut. A remote attacker on the adjacen…7.5
- CVE-2026-16447A vulnerability has been found in D-Link DNS-320 1.0.2. Impa…7.3
- CVE-2026-16448A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-3…6.3
- CVE-2026-16449A vulnerability was determined in zsadmin2025 ZS-Admin up to…6.3
- CVE-2026-1645The Hostel plugin for WordPress is vulnerable to Stored Cros…4.4
Are you affected by CVE-2026-16443?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
