CVE-2026-2603
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Pr
CVSS
8.1
Alto
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 18 mar 2026 · Última mod.: 15 jul 2026 · CWE-306
0.4%EPSS · 30 días0.4%
2026-06-302026-07-20
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provider is disabled, leading to unauthorized authentication.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3925
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3926
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3947
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3948
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-2603
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2440300
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3925
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3926
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3947
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:3948
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-2603
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2440300
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2440300
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2603.json
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-32489.8 CRÍ100.0%
KEV—80Langflow Missing Authentication Vulnerability6dCVE-2024-116809.8 CRÍ99.8%
KEV—80ProjectSend Improper Authentication Vulnerability6dCVE-2026-561645.3 MED92.1%
KEV—78Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability6dCVE-2026-468179.8 CRÍ60.4%
KEV—68Oracle E-Business Suite Improper Privilege Management Vulnerability5dCVE-2022-245629.8 CRÍ98.9%
——30In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.12dCVE-2026-411769.8 CRÍ98.3%
——29Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue.6d