The open-source IAM system Keycloak 26.6 promotes five features to production status – including federated client ...
A pre‑authentication bug in SAML Web SSO, combined with weak access controls and cryptography, allows attackers to escalate privileges and achieve remote code execution.