Impact
A flaw resides in Keycloak’s ClientResource component when Fine‑Grained Admin Permissions (FGAP) v2 is enabled. A delegated administrator, who should only manage a subset of clients, can attach or remove hidden client scopes that are outside his authorized view, thereby inserting unauthorized scopes into the security tokens issued to end users. These injected scopes can grant downstream applications higher levels of access than intended. The weakness represents an improper access control (CWE‑284) and an authorization bypass via user‑controlled keys (CWE‑639).
Affected Systems
Red Hat Build of Keycloak, Red Hat Data Grid 8, JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7 are affected. No specific version information is provided in the CVE payload.
Risk and Exploitability
The vulnerability can be exploited by any user who has been delegated administrative privileges under FGAP v2, typically through the Keycloak admin console or its REST API. After authenticating, the attacker can identify client‑scope identifiers that are hidden from their view and then assign or remove those scopes to a client, causing the altered scopes to appear in the bearer tokens that end users receive. This can lead to unintended privilege elevation or token injection. The CVSS score of 5.4 places the flaw in the medium severity range, but the EPSS score of < 1 % indicates a very low likelihood of current exploitation, and it is not listed in the CISA KEV catalog.
OpenCVE Enrichment