Impersonation Vulnerability in Keycloak by Red Hat
CVE-2026-17526

7.2HIGH

What is CVE-2026-17526?

Keycloak, an open-source identity and access management solution developed by Red Hat, contains a vulnerability that allows users with the impersonation role to impersonate realm administrators. This significant security flaw enables unauthorized users to gain full administrative privileges over the realm. Consequently, attackers can manage users, clients, and roles without proper authorization, leading to potential misuse of sensitive information and critical system settings.

Affected Version(s)

Red Hat build of Keycloak 26.4 26.4-26

Red Hat build of Keycloak 26.4 26.4-26

Red Hat build of Keycloak 26.4 26.4.16-2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Orionexe for reporting this issue.
.