Skip to finding
important · Identity — Keycloak

A delegated Keycloak user administrator can promote itself to realm administrator through group membership.

Affects

Keycloak, an identity-and-access-management server, including Red Hat Build of Keycloak and Red Hat Single Sign-On deployments.

In realms that map administration through a group, a manage-users session can add its own account because the REST endpoint does not evaluate the roles inherited from that group.

Detail and 2 sources

No fixed release or generally applicable mitigation has been published.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026