User Update Flaw in Keycloak Admin REST API from Red Hat
CVE-2026-97177

6.6MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
24 September 2026

What is CVE-2026-97177?

A vulnerability exists in the Keycloak Admin REST API where the user update mechanism fails to properly verify password reset permissions when Fine-Grained Admin Permissions are enabled. This oversight allows a delegated administrator, who should not have access to reset user passwords, to alter a user’s credentials, potentially granting them unauthorized access to user accounts.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Paul Bottinelli of Trail of Bits in collaboration with OpenAI for reporting this issue.
.