PatchSiren cyber security CVE debrief
CVE-2026-3009 Red Hat CVE debrief
A security flaw in Keycloak's IdentityBrokerService.performLogin endpoint allows authentication to proceed using a disabled Identity Provider (IdP). An attacker who knows the IdP alias can reuse a previously generated login request to bypass administrative restrictions. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.
- Vendor
- Red Hat
- Product
- Red Hat build of Keycloak 26.4
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-05
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-03-05
- Advisory updated
- 2026-09-14
Who should care
Defenders managing Keycloak deployments, especially those using external IdPs, should assess exposure and verify access control configurations. This includes verifying the effectiveness of their access control configurations and monitoring for suspicious authentication attempts through disabled IdPs.
Why it matters
CVE-2026-3009 allows authentication to proceed using a disabled Identity Provider (IdP) in Keycloak, undermining access control enforcement. Defenders managing Keycloak deployments should verify exposure, assess access control configurations, and monitor for suspicious authentication attempts.
- Verification of Keycloak deployments for exposure to unauthorized authentication
- Assessment of access control configurations and effectiveness
- Monitoring for suspicious authentication attempts through disabled IdPs
- Review and update of administrative restrictions on IdP usage
Technical summary
The IdentityBrokerService.performLogin endpoint in Keycloak allows authentication to proceed with a disabled Identity Provider (IdP). An attacker knowing the IdP alias can reuse a previous login request, bypassing administrative restrictions. This undermines access control enforcement, potentially allowing unauthorized authentication through a disabled external provider. Defenders managing Keycloak deployments, especially those using external IdPs, should assess exposure and verify access control configurations. The CVE record and NVD entry provide details on the vulnerability. Vendor advisories from Red Hat offer additional context and mitigation guidance.
Defensive priority
Defenders should prioritize verifying exposure of Keycloak deployments, especially those using external IdPs, and assess the effectiveness of their access control configurations.
Recommended defensive actions
- Verify Keycloak deployments for exposure, especially those using external IdPs
- Assess access control configurations and effectiveness
- Review and update administrative restrictions on IdP usage
- Monitor for suspicious authentication attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Vendor advisories from Red Hat offer additional context and mitigation guidance. The IdentityBrokerService.performLogin endpoint in Keycloak allows authentication to proceed with a disabled Identity Provider (IdP). An attacker knowing the IdP alias can reuse a previous login request, bypassing administrative restrictions. This undermines access control enforcement, potentially allowing unauthorized authentication through a disabled external provider. Defenders should
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3009 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3009
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3009 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3009
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:3947
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:3948
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-3009
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.