PT-2026-93820 · Keycloak · Keycloak
CVE-2026-17526
·
Published
2026-09-16
·
Updated
2026-09-19
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Keycloak versions prior to 26.7.4
Description
A flaw exists where a user assigned the impersonation role can impersonate a realm administrator. This privilege escalation allows an attacker to obtain full administrative control over the realm, enabling the management of users, clients, and roles.
Recommendations
Update to version 26.7.4.
Restrict the assignment of the impersonation role to users below the administrator level as a mitigation measure.
Fix
DoS
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak