Executive brief
Keycloak, an open-source identity and access management solution, contains a vulnerability in its Authorization Services. An authenticated user could potentially view, modify, or delete security resources belonging to other applications within the same environment if they know the resource's unique identifier. This could lead to unauthorized data access or the disruption of security policies for other services.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Keycloak's User-Managed Access (UMA) Protection API endpoint. The root cause is a failure to properly validate that the requesting authenticated client owns the resource associated with a provided UUID. An attacker with a valid account and knowledge of a target resource's UUID can bypass authorization checks to perform GET, PUT, and DELETE operations. This allows for unauthorized information disclosure and modification of resources across different Resource Servers within the same realm. The vulnerability is addressed in version 26.6.2.
Affected products
- Keycloak keycloak-services < 26.6.2
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-06-30: patched: Advisory updated with patch information