← Back

CVE-2026-9795

nvd nist
Published: May 28, 2026Modified: Jul 15, 2026

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Exploitability: 1.0 / Impact: 5.8
Source: secalert@redhat.com (Secondary)

Description

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the injected role to be projected into a user's authentication token when they access the modified client. This could lead to unauthorized privilege escalation within the Keycloak realm.

Affected (1)

1 product
Build Of Keycloak
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (13)

Source: secalert@redhat.com
MitigationVendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
MitigationVendor Advisory
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Issue TrackingVendor Advisory

Timeline

No history available yet.