Privilege Escalation Risk in Keycloak Products by Red Hat
CVE-2026-4629
6.5MEDIUM
What is CVE-2026-4629?
A security flaw exists in Keycloak that allows a highly privileged user, with the 'manage-clients' permission, to exploit the system by injecting a hardcoded role mapper into any client. This action bypasses existing scope restrictions and enables the injection of the 'realm-admin' role into generated tokens. As a result, this can lead to privilege escalation, granting full administrative access to the realm and potentially compromising the entire system security.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Daniel Peters (Operating Intelligence Inc.), Lior Moshe (Operating Intelligence Inc.), and Uri Rolls (Operating Intelligence Inc.) for reporting this issue.