Privilege Escalation Vulnerability in Keycloak's Fine-Grained Admin Permissions
CVE-2026-9795
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 28 May 2026
What is CVE-2026-9795?
A significant flaw exists in the Fine-Grained Admin Permissions (FGAPv2) feature of Keycloak. This vulnerability allows an administrator with restricted client management permissions to exploit the system by assigning any realm role to a client's scope mapping. As a result, this bypasses the intended security controls within the platform. When a user accesses the compromised client, the injected role is projected into their authentication token, which could facilitate unwanted privilege escalation within the Keycloak realm, potentially leading to unauthorized access and manipulation of sensitive resources.
Affected Version(s)
Red Hat build of Keycloak 26.6 26.6.4-2
Red Hat build of Keycloak 26.6 26.6-8
Red Hat build of Keycloak 26.6 26.6-8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved