rootpwn

medium · CVSS v3 6.6

CVE-2026-94000

A privilege escalation vulnerability exists in the Admin REST API of Keycloak within group-membership endpoints. The application fails to va

Overview

A privilege escalation vulnerability exists in the Admin REST API of Keycloak within group-membership endpoints. The application fails to validate whether a target group grants administrative privileges prior to adding a user. This allows a delegated administrator with limited rights to elevate their access to a high-privilege group and compromise the realm.

Description

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.

Impact

This vulnerability impacts the integrity and confidentiality of the Keycloak identity and access management system. An attacker with low-level delegated administrator privileges can exploit this flaw to achieve complete administrative control over an affected realm. The confidentiality, integrity, and availability of all services secured by that realm are subsequently at risk.

Remediation

Apply the official security updates or patches provided by the Keycloak project as soon as they become available. Audit existing delegated administrator roles and group memberships to identify any unauthorized privilege grants. Restrict access to the Admin REST API using network segmentation and Web Application Firewalls where appropriate.

Risk context

Rated with a CVSS v3 score of 6.6 (Medium), this vulnerability requires authenticated access with existing delegated administrative permissions to exploit. Organizations should prioritize remediation based on their exposure of the Keycloak Admin REST API and reliance on delegated administration models.

Affected products

  • Keycloak Keycloak

Scores

Severity
medium
CVSS v2
6.8
CVSS v3
6.6
CVSS v4
EPSS

Keycloak Privilege Escalation REST API IAM Access Control Medium Severity

← All CVEs