Executive brief
A security flaw in Keycloak's identity management system allows a user with limited administrative access to take over the entire security realm. By exploiting a missing check in the group management interface, an attacker can move highly privileged groups under their own control. This allows the attacker to reset administrator passwords and gain full access to sensitive customer data and system configurations.
Technical details
A vulnerability exists in the GroupResource.addChild() endpoint of the Keycloak Admin REST API due to a missing authorization check. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an authenticated attacker with management rights over at least one low-privilege group can reparent a highly privileged group (such as one with the realm-admin role) to be a child of their managed group. Because Keycloak group permissions are hierarchical, the attacker inherits management and password-reset capabilities over the members of the moved group. This allows for account takeover of high-privilege administrators and a complete compromise of the realm's confidentiality, integrity, and availability.
Affected products
- Red Hat Keycloak Not specified
- Red Hat Red Hat Build of Keycloak Not specified
Timeline
- 2026-05-20: other: Reported via Bugzilla
- 2026-06-25: disclosed: NVD publication date