All verified exploits

CVE-2026-3009 Disabled Identity Provider Authentication Bypass

Deterministic high Keycloak Added cve-verified-cve-2026-3009

Detects Keycloak instances where the IdentityBrokerService.performLogin endpoint allows authentication via a disabled Identity Provider. Versions before 26.2.14, 26.4.10, and 26.5.5 are affected. An attacker who knows the IdP alias can bypass admin-imposed IdP restrictions.

Is your app exploitable through CVE-2026-3009?

Scan your domain free