Описание
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to already hold a delegated administrator role with specific client management permissions and knowledge of internal resource identifiers (UUIDs). Successful exploitation allows an attacker to bypass fine-grained authorization boundaries to modify the contents of tokens issued by Keycloak, potentially leading to unauthorized actions in downstream applications. The vulnerability's root cause is a missing authorization check on the referenced client scope during the assignment process in the admin REST API.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Keycloak | keycloak-services | Not affected | ||
| Red Hat Build of Keycloak | rhbk-openshift-rhel9/rhbk-openshift-rhel9 | Not affected | ||
| Red Hat Data Grid 8 | keycloak-services | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-services | Not affected | ||
| Red Hat Single Sign-On 7 | keycloak-services | Not affected | ||
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2026:50847 | 05.08.2026 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:50847 | 05.08.2026 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator | Fixed | RHSA-2026:50847 | 05.08.2026 |
| Red Hat build of Keycloak 26.4.14 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:50846 | 05.08.2026 |
| Red Hat build of Keycloak 26.6 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2026:50849 | 05.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.
A flaw was found in the ClientResource component of Keycloak's admin s ...
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control over specific clients, to attach or remove hidden client scopes that they are not authorized to see or manage. As a result, an attacker could inject unauthorized data or permissions into the security tokens issued to end-users, potentially tricking other applications into granting higher levels of access than intended.
EPSS
5.4 Medium
CVSS3