Количество 4
Количество 4

CVE-2025-7784
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

CVE-2025-7784
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.
CVE-2025-7784
A flaw was found in the Keycloak identity and access management system ...
GHSA-27gp-8389-hm4w
Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2025-7784 A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm. | CVSS3: 6.5 | 0% Низкий | 21 день назад |
![]() | CVE-2025-7784 A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm. | CVSS3: 6.5 | 0% Низкий | 20 дней назад |
CVE-2025-7784 A flaw was found in the Keycloak identity and access management system ... | CVSS3: 6.5 | 0% Низкий | 20 дней назад | |
GHSA-27gp-8389-hm4w Keycloak Privilege Escalation Vulnerability in Admin Console (FGAPv2 Enabled) | CVSS3: 6.5 | 0% Низкий | 8 дней назад |
Уязвимостей на страницу