Executive brief
Keycloak is an open-source identity and access management system that organizations use to control user access and permissions across applications. A vulnerability allows users with the impersonation role to bypass security controls and assume the identity of realm administrators, gaining complete control over user accounts, application access, and permission settings. An attacker exploiting this could access sensitive data, create unauthorized accounts, or lock legitimate users out of critical systems.
Technical details
The vulnerability is a privilege escalation flaw in Keycloak's impersonation functionality that allows a user with the impersonation role to impersonate realm administrators without proper authorization checks. The root cause lies in insufficient validation of authorization boundaries when the impersonation feature is used. An attacker with the impersonation role can directly escalate privileges by impersonating an administrative account, gaining full realm-level control including user management, client configuration, and role assignment. No special network access or user interaction is required beyond having the impersonation role assigned. Patches are expected from Red Hat/Keycloak project, and users should monitor official security advisories for remediation.
Affected products
- Keycloak Keycloak <UNKNOWN>
Timeline
- 2026-09-16: disclosed