Improper Access Control in Keycloak Allows Privilege Escalation
CVE-2026-11577

7.2HIGH

What is CVE-2026-11577?

A vulnerability has been identified in Keycloak where a limited administrator can exploit an improper access control flaw in the POST /admin/realms/{realm}/partialImport endpoint. This weakness enables the limited admin to circumvent Fine-Grained Admin Permissions (FGAP), allowing them to escalate their privileges to that of a full realm administrator by erroneously importing users with realm-admin role mappings. This could result in unauthorized access to sensitive realm configurations and operations, compromising the overall security of the system.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Andrii Ilin (10Guards) for reporting this issue.
.