Impact
A flaw in Keycloak’s LDAP storage provider allows a delegated administrator to perform a search using a specific LDAP entry Distinguished Name (DN) that bypasses the configured user DN boundary. Because the provider does not validate the search boundary, the lookup can return entries located outside the intended subtree, revealing account information that the administrator is not authorized to see and potentially importing those accounts into the local Keycloak storage. The primary consequence is loss of confidentiality and accidental expansion of the local user base.
Affected Systems
The vulnerability affects Red Hat’s build of Keycloak 26.4, 26.4.14, 26.6, and 26.6.5, as well as Red Hat Data Grid 8, the JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. Any installation that uses the LDAP storage provider and assigns delegated administrator permissions is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is below 1%, suggesting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack, as described, requires an authenticated delegated administrator who can craft a search with a specific entry DN. The observed risk is limited to environments where many users have delegated administrator roles; the potential for data disclosure exists, but the probability remains low.
OpenCVE Enrichment