PatchSiren cyber security CVE debrief
CVE-2026-18217 Red Hat CVE debrief
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- LOW 3.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-08-07
Who should care
Administrators and users of Keycloak, especially those with wildcard redirect URLs configured, should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also verify user authentication and authorization processes and track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators, platform managers, vulnerability management teams, and security teams should prioritize defensive review required; verify Keycloak configurations and monitor authentication requests. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Limited source detail suggests that defenders should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. They should also review compensating controls for exposed systems while remediation is scheduled and verified and track exceptions, retest remediated assets, and close the item only after evidence is documented. Limited source detail suggests that defenders should review Keycloak configurations for wildcard redirect URLs and monitor authentication requests for potential malicious activity. They should also verify user authentication and authorization processes and track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators, platform managers, vulnerability management teams, and security teams should prioritize defensive review required; verify Keycloak configurations and monitor authentication requests. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Limited source detail suggests that defenders should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. They should also review compensating controls for exposed systems while remediation is and
Technical summary
The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. Keycloak appends its legitimate response to the attacker's parameters, potentially leading to a user being logged into the wrong account. This issue requires review of compensating controls for exposed systems while remediation is scheduled and verified.
Defensive priority
Low-priority defensive review required; verify Keycloak configurations and monitor authentication requests.
Recommended defensive actions
- Review Keycloak configurations for wildcard redirect URLs
- Monitor authentication requests for potential malicious activity
- Verify user authentication and authorization processes
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Evidence from Redhat indicates a potential vulnerability in Keycloak's SAML protocol implementation. Further review of configurations and authentication requests is necessary to verify affected scope and to confirm whether affected product deployments exist in managed environments. Limited source detail suggests that defenders should review Keycloak configurations for wildcard redirect URLs and monitor authentication requests for potential malicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18217 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18217
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18217 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18217
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-18217
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.