PatchSiren cyber security CVE debrief
CVE-2026-18217 Red Hat CVE debrief
A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. When a user authenticates, Keycloak appends its legitimate response to the attacker's parameters. This can cause some service providers to process the attacker's data instead of the real login information, potentially leading to a user being logged into the wrong account.
- Vendor
- Red Hat
- Product
- Red Hat Build of Keycloak
- CVSS
- LOW 3.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators and users of Keycloak, especially those with wildcard redirect URLs configured, should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also verify user authentication and authorization processes and track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators, platform managers, vulnerability management teams, and security teams should prioritize defensive review required; verify Keycloak configurations and monitor authentication requests. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Limited source detail suggests that defenders should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. They should also review compensating controls for exposed systems while remediation is scheduled and verified and track exceptions, retest remediated assets, and close the item only after evidence is documented. Limited source detail suggests that defenders should review Keycloak configurations for wildcard redirect URLs and monitor authentication requests for potential malicious activity. They should also verify user authentication and authorization processes and track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators, platform managers, vulnerability management teams, and security teams should prioritize defensive review required; verify Keycloak configurations and monitor authentication requests. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Limited source detail suggests that defenders should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. They should also review compensating controls for exposed systems while remediation is and
Technical summary
The issue occurs when Keycloak handles SAML authentication requests using the HTTP-Redirect binding. If a client is configured with a wildcard redirect URL, an attacker can craft a request that includes malicious parameters. Keycloak appends its legitimate response to the attacker's parameters, potentially leading to a user being logged into the wrong account. This issue requires review of compensating controls for exposed systems while remediation is scheduled and verified.
Defensive priority
Low-priority defensive review required; verify Keycloak configurations and monitor authentication requests.
Recommended defensive actions
- Review Keycloak configurations for wildcard redirect URLs
- Monitor authentication requests for potential malicious activity
- Verify user authentication and authorization processes
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Evidence from Redhat indicates a potential vulnerability in Keycloak's SAML protocol implementation. Further review of configurations and authentication requests is necessary to verify affected scope and to confirm whether affected product deployments exist in managed environments. Limited source detail suggests that defenders should review Keycloak configurations for wildcard redirect URLs and monitor authentication requests for potential malicious activity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T08:16:28.037Z and has not been modified since then.