CVE-2026-16443: Improper Verification of Cryptographic Signature in Red Hat Red Hat Build of Keycloak
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
AI Analysis
Technical Summary
The vulnerability exists in the keycloak-services component's SAML metadata import process within Red Hat Build of Keycloak. When importing identity provider metadata missing specific key usage attributes, the system disables signature validation for SAML responses despite the presence of a signing certificate. This improper verification of cryptographic signatures (CWE-347) enables an unauthenticated attacker to forge SAML responses and impersonate users, gaining full access to their accounts. Red Hat has assessed this issue as Important due to the potential for unauthenticated account takeover under common configurations. No official fix or mitigation currently meets Red Hat's standards, and users are advised to monitor Red Hat advisories for updates.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to forge SAML responses and gain unauthorized access to user accounts by knowing their external identifiers. This results in a complete compromise of confidentiality and integrity of affected user accounts. The vulnerability does not impact availability. The attack complexity is high, and no privileges or user interaction are required for exploitation.
Mitigation Recommendations
As per the Red Hat advisory, no effective mitigation or patch is currently available that meets the criteria for ease of use, applicability to the widespread installation base, or stability. Users should monitor the official Red Hat advisory for future updates or fixes. Until a fix is released, consider restricting access to the affected service or applying any vendor-recommended temporary controls if available.
CVE-2026-16443: Improper Verification of Cryptographic Signature in Red Hat Red Hat Build of Keycloak
Description
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.
CVSS v3.1
Score 7.4high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the keycloak-services component's SAML metadata import process within Red Hat Build of Keycloak. When importing identity provider metadata missing specific key usage attributes, the system disables signature validation for SAML responses despite the presence of a signing certificate. This improper verification of cryptographic signatures (CWE-347) enables an unauthenticated attacker to forge SAML responses and impersonate users, gaining full access to their accounts. Red Hat has assessed this issue as Important due to the potential for unauthenticated account takeover under common configurations. No official fix or mitigation currently meets Red Hat's standards, and users are advised to monitor Red Hat advisories for updates.
Potential Impact
An unauthenticated attacker can exploit this vulnerability to forge SAML responses and gain unauthorized access to user accounts by knowing their external identifiers. This results in a complete compromise of confidentiality and integrity of affected user accounts. The vulnerability does not impact availability. The attack complexity is high, and no privileges or user interaction are required for exploitation.
Mitigation Recommendations
As per the Red Hat advisory, no effective mitigation or patch is currently available that meets the criteria for ease of use, applicability to the widespread installation base, or stability. Users should monitor the official Red Hat advisory for future updates or fixes. Until a fix is released, consider restricting access to the affected service or applying any vendor-recommended temporary controls if available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-21T07:41:14.816Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-16443","vendor":"Red Hat"}]
Threat ID: 6a7344b3bf8831d539fd0bfc
Added to database: 08/05/2026, 14:12:03 UTC
Last enriched: 08/05/2026, 14:26:47 UTC
Last updated: 08/05/2026, 15:28:15 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.