PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18967 Red Hat CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:29.413Z and has not been modified since then. The SAML broker component of Keycloak fails to enforce the OneTimeUse condition in SAML assertions, allowing an attacker to replay valid, unused assertions. This flaw could enable session hijacking and unauthorized access as the victim user. Keycloak instances configured as SAML brokers using the IdP-Initiated flow are affected. Defenders should verify configurations, monitor for suspicious activity, and consider compensating controls. Evidence is limited, primarily from official CVE and NVD records.

Vendor
Red Hat
Product
Red Hat Build of Keycloak
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Administrators of Keycloak instances configured as SAML brokers using the IdP-Initiated flow should verify their configurations and monitor for suspicious activity. Security teams and vulnerability management teams should prioritize patching or mitigating this vulnerability, as it could lead to unauthorized access and session hijacking. Additionally, operators and platform teams should be aware of the potential impact on user sessions and system security.

Technical summary

A flaw in Keycloak's SAML broker component allows an attacker to replay valid, unused SAML assertions, potentially hijacking a user's session. This occurs when Keycloak is configured as a SAML broker using the IdP-Initiated flow and fails to enforce the OneTimeUse condition in SAML assertions. The technical impact is that an attacker could gain unauthorized access to the system as the victim user, leading to potential lateral movement and further exploitation.

Defensive priority

Medium priority due to potential session hijacking

Recommended defensive actions

  • Verify Keycloak configuration and enforce OneTimeUse condition
  • Monitor for suspicious SAML assertion activity
  • Implement compensating controls for session management
  • Review vendor patch guidance for Keycloak updates
  • Conduct exposure review for affected Keycloak instances
  • Inventory affected assets and track patch status
  • Establish monitoring for unusual session activity

Evidence notes

The evidence for this CVE is limited, primarily based on official records from CVE.org and NVD. The SAML broker component of Keycloak fails to enforce the OneTimeUse condition in SAML assertions, which could allow an attacker to replay valid, unused assertions. Defenders should verify Keycloak configurations, especially those using the IdP-Initiated flow, and monitor for suspicious SAML assertion activity. Further verification is needed to determine the full scope of affected systems and potential impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:29.413Z and has not been modified since then.