PT-2026-53859 · Red Hat · Keycloak

·

CVE-2026-12388

·

Published

2026-06-30

·

Updated

2026-06-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the Identity Provider (IdP) mapper component, which manages the mapping of user information from external services to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this by creating a "Hardcoded Role" mapper to assign high-level administrative roles, such as realm-admin, to themselves or other users. This allows a restricted administrator to bypass security checks and obtain full control over the entire realm.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12388

Affected Products

Keycloak