CVE-2026-3009 Details
Description
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.
An authentication bypass vulnerability has been identified in the Keycloak Identity Broker Service, specifically within the performLogin endpoint. This flaw allows authentication to proceed through an Identity Provider (IdP) that has been disabled by an administrator. The vulnerability arises because the login process does not properly re-validate the IdP's status at the time of authentication. As a result, an attacker who knows the IdP alias can exploit this issue by reusing a previously generated login request, effectively bypassing administrative controls and potentially gaining unauthorized access via a disabled external provider.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:3947 | redhat-SADP | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:3948 | redhat-SADP | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-3009 | redhat-SADP | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2441867 | redhat-SADP | Issue TrackingVendor Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.json | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:3947 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:3948 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-3009 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2441867 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | redhat-SADP |
| CWE-863 | Incorrect Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of keycloak | 26.4 26.4.10 |
CPE
Remediation
| |
| redhat jboss enterprise application platform | 8.0 |
CPE
Remediation
| |
| redhat jboss enterprise application platform expansion pack | All versions |
CPE
Remediation
| |
| redhat single sign-on | 7.0 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | redhat-SADP |
| Sep 14, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 4, 2026 | CVE Modified | redhat-SADP |
| Aug 3, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 24, 2026 | CVE Modified | [email protected] |
| Mar 10, 2026 | Initial Analysis | [email protected] |
| Mar 5, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | New CVE Received | [email protected] |