CVE-2026-1190 | Red Hat Keycloak SAML Brokering SubjectConfirmationData xml validation (Nessus ID 300554 / WID-SEC-2026-0147)
A vulnerability has been found in Red Hat Keycloak and classified as critical. This affects the function SubjectConfirmationData of the component SAML Brokering. The manipulation leads to missing xml validation.
This vulnerability is referenced as CVE-2026-1190. The attack needs to be initiated within the local network. No exploit is available.