PT-2026-98400 · Red Hat · Keycloak

CVE-2026-96448

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw exists in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak. The issue occurs during the verification process of whether a delegated administrator has the necessary permissions to assign a specific role to a user. Because the system fails to inspect composite roles—roles that are composed of other roles—to identify the permissions they contain, an administrator with restricted privileges can assign a composite role that includes full administrative control. This allows an attacker to obtain complete management access over the entire realm.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96448

Affected Products

Keycloak