CVE-2024-8698 is a flaw in Keycloak's SAML signature validation logic in the XMLSignatureUtil class. The vulnerable code determines whether an XML signature applies to the entire SAML document or only to specific assertions based on the signature's position within the XML document, instead of using the XML Signature Reference element that explicitly identifies the signed element. Because of this incorrect trust decision, an attacker can craft SAML responses that cause Keycloak to accept a manipulated response or assertion as properly signed when it is not validated as intended.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Java proof-of-concept exploit for CVE-2024-8698, targeting Keycloak's SAML implementation. The main code is in 'src/main/java/test/Main.java', which constructs a SAML response containing a valid assertion and signature, then manipulates the XML to clone the assertion, change the NameID to 'admin@abc.co', and append the forged assertion to the response. This technique is designed to test for SAML signature wrapping or assertion injection vulnerabilities, where a SAML Service Provider (such as Keycloak) may incorrectly process the forged assertion, potentially granting unauthorized access. The exploit does not include network delivery or automation; it outputs the manipulated SAML response for use in further testing. The repository includes standard Java project files and a README linking to a technical analysis. The endpoints in the SAML XML are local addresses, but in practice, the exploit would target a real Keycloak instance or other SAML SP. The code demonstrates the vulnerability but does not weaponize it for automated exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Keycloak SAML signature validation bypass in XMLSignatureUtil that can allow crafted SAML responses to pass validation, enabling impersonation and/or privilege escalation.
A Keycloak SAML response verification flaw that can allow privilege escalation due to improper verification of SAML responses.
A Keycloak SAML response verification flaw that can lead to privilege escalation due to improper verification of SAML responses.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.