HIGHMaven

Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator

Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator

CVE-2026-3009Published 6 months agoUpdated 1 week agoSource: OSV

Affected packages

  • org.keycloak:keycloak-servicesbefore 26.5.5

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Keycloak allows authentication using an Identity Provider (IdP) even after it has been disabled by an administrator | HackTribune