PT-2026-98400 · Red Hat · Keycloak
CVE-2026-96448
·
Published
2026-09-25
·
Updated
2026-09-26
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A flaw exists in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak. The issue occurs during the verification process of whether a delegated administrator has the necessary permissions to assign a specific role to a user. Because the system fails to inspect composite roles—roles that are composed of other roles—to identify the permissions they contain, an administrator with restricted privileges can assign a composite role that includes full administrative control. This allows an attacker to obtain complete management access over the entire realm.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak