PT-2026-93820 · Keycloak · Keycloak

CVE-2026-17526

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak versions prior to 26.7.4
Description A flaw exists where a user assigned the impersonation role can impersonate a realm administrator. This privilege escalation allows an attacker to obtain full administrative control over the realm, enabling the management of users, clients, and roles.
Recommendations Update to version 26.7.4. Restrict the assignment of the impersonation role to users below the administrator level as a mitigation measure.

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17526

Affected Products

Keycloak