PT-2026-53859 · Red Hat · Keycloak
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A flaw exists in the Identity Provider (IdP) mapper component, which manages the mapping of user information from external services to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this by creating a "Hardcoded Role" mapper to assign high-level administrative roles, such as
realm-admin, to themselves or other users. This allows a restricted administrator to bypass security checks and obtain full control over the entire realm.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak