Impersonation Vulnerability in Keycloak by Red Hat
CVE-2026-17526
7.2HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-17526?
Keycloak, an open-source identity and access management solution developed by Red Hat, contains a vulnerability that allows users with the impersonation role to impersonate realm administrators. This significant security flaw enables unauthorized users to gain full administrative privileges over the realm. Consequently, attackers can manage users, clients, and roles without proper authorization, leading to potential misuse of sensitive information and critical system settings.
Affected Version(s)
Red Hat build of Keycloak 26.4 26.4-26
Red Hat build of Keycloak 26.4 26.4-26
Red Hat build of Keycloak 26.4 26.4.16-2
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Orionexe for reporting this issue.