PT-2026-55550 · Red Hat · Keycloak
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A flaw exists in the
ClientResource component of the admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator with limited control over specific clients to attach or remove hidden client scopes they are not authorized to manage. This could enable an attacker to inject unauthorized data or permissions into security tokens issued to end-users, potentially leading other applications to grant higher access levels than intended.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak