Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14614

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to already hold a delegated administrator role with specific client management permissions and knowledge of internal resource identifiers (UUIDs). Successful exploitation allows an attacker to bypass fine-grained authorization boundaries to modify the contents of tokens issued by Keycloak, potentially leading to unauthorized actions in downstream applications. The vulnerability's root cause is a missing authorization check on the referenced client scope during the assignment process in the admin REST API.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Keycloakkeycloak-servicesNot affected
Red Hat Build of Keycloakrhbk-openshift-rhel9/rhbk-openshift-rhel9Not affected
Red Hat Data Grid 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesNot affected
Red Hat build of Keycloak 26.4rhbk/keycloak-operator-bundleFixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9FixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4rhbk/keycloak-rhel9-operatorFixedRHSA-2026:5084705.08.2026
Red Hat build of Keycloak 26.4.14rhbk/keycloak-rhel9FixedRHSA-2026:5084605.08.2026
Red Hat build of Keycloak 26.6rhbk/keycloak-operator-bundleFixedRHSA-2026:5084905.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2496889keycloak-services: keycloak-services: FGAP v2 client scope assignment bypass via ClientResource

EPSS

Процентиль: 8%
0.00185
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.

CVSS3: 5.4
nvd
около 2 месяцев назад

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.

CVSS3: 5.4
debian
около 2 месяцев назад

A flaw was found in the ClientResource component of Keycloak's admin s ...

CVSS3: 5.4
github
около 2 месяцев назад

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.

EPSS

Процентиль: 8%
0.00185
Низкий

5.4 Medium

CVSS3