Detects Keycloak instances where the IdentityBrokerService.performLogin endpoint allows authentication via a disabled Identity Provider. Versions before 26.2.14, 26.4.10, and 26.5.5 are affected. An attacker who knows the IdP alias can bypass admin-imposed IdP restrictions.
Is your app exploitable through CVE-2026-3009?
Scan your domain free