important · Identity — Keycloak
A delegated Keycloak user administrator can promote itself to realm administrator through group membership.
Affects
Keycloak, an identity-and-access-management server, including Red Hat Build of Keycloak and Red Hat Single Sign-On deployments.
In realms that map administration through a group, a manage-users session can add its own account because the REST endpoint does not evaluate the roles inherited from that group.
Detail and 2 sources
No fixed release or generally applicable mitigation has been published.