Weakness in Role Assignment for Keycloak by Red Hat
CVE-2026-96448
6.6MEDIUM
What is CVE-2026-96448?
A critical security flaw exists in the Fine-Grained Admin Permissions (FGAP v2) feature of the Keycloak identity and access management solution. The vulnerability arises from an oversight in the permission-checking mechanism when a delegated administrator attempts to assign roles. Specifically, the system fails to adequately evaluate composite roles, which can hold additional permissions. Consequently, an administrator with restricted rights has the potential to assign a role that inadvertently confers full administrative control over the entire realm to the user, a scenario that could be exploited by malicious actors to gain unauthorized access to sensitive data and system settings.