6.5
CVE-2026-4629
- EPSS 0.33%
- Veröffentlicht 30.06.2026 12:00:28
- Zuletzt bearbeitet 05.08.2026 19:17:31
- CVE-Watchlists
- Unerledigt
Keycloak: keycloak: privilege escalation through hardcoded role mapper injection
A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege escalation and full administrative access to the realm.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Build Of Keycloak Version-
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.25 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
https://bugzilla.redhat.com/show_bug.cgi?id=2450244
https://access.redhat.com/errata/RHSA-2026:50846
https://access.redhat.com/errata/RHSA-2026:50847
https://access.redhat.com/security/cve/CVE-2026-4629