Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12388

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns high-level administrative roles (like realm-admin) to themselves or others. This allows a restricted administrator to bypass security checks and gain full control over the entire realm.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00233
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.5
redhat
около 2 месяцев назад

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns high-level administrative roles (like realm-admin) to themselves or others. This allows a restricted administrator to bypass security checks and gain full control over the entire realm.

CVSS3: 6.5
debian
около 2 месяцев назад

A flaw was found in the Identity Provider (IdP) mapper component of Ke ...

CVSS3: 6.5
github
около 2 месяцев назад

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is mapped to Keycloak users. An administrator with limited permissions to manage identity providers can exploit this flaw by creating a "Hardcoded Role" mapper that assigns high-level administrative roles (like realm-admin) to themselves or others. This allows a restricted administrator to bypass security checks and gain full control over the entire realm.

EPSS

Процентиль: 14%
0.00233
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266