Junglewise Threat Intelligence

CVE-2026-4628: Keycloak improper access control in UMA resource_set endpoint

CVE-2026-4628 · Severity: medium · CVSS 4.3 · Published 2026-03-23

Technologies: org.keycloak:keycloak-services (Maven), Keycloak. Vendors: Maven, Keycloak.

Executive brief

Keycloak, an open-source identity and access management solution, contains a security flaw in its resource management component. An attacker with valid login credentials can bypass security restrictions to modify protected resources that should be locked. This could lead to unauthorized changes to sensitive data or system configurations, potentially compromising the integrity of the identity management system.

Technical details

An improper access control vulnerability (CWE-284) exists in Keycloak's User-Managed Access (UMA) resource_set endpoint. The vulnerability stems from incomplete enforcement of access control checks during HTTP PUT operations. Specifically, an attacker with valid credentials can bypass the 'allowRemoteResourceManagement=false' configuration setting. This allows unauthorized modification of protected resources via the resource_set endpoint. The issue affects versions up to and including 26.6.0; as of the advisory date, no patched version is specified.

Affected products

  • Keycloak Keycloak <= 26.6.0

Timeline

  • 2026-03-23: disclosed
  • 2026-03-23: advisory

References

Related threats