Impact
An attacker with a standard user account and a limited Initial Access Token can exploit a flaw in Keycloak’s Dynamic Client Registration component. The default policy fails to validate the claim path for User Property mappers, allowing them to write values to internal claim locations. This enables forging administrative roles directly into the user’s access token, giving the attacker the ability to take over other clients, steal confidential secrets, and potentially gain full administrative control over the realm.
Affected Systems
Affected products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign-On 7. Affected versions were not specified in the advisory, so this vulnerability applies to any releases that retain the default Dynamic Client Registration policy.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, requiring only a valid user account and a standard Initial Access Token. Once the attacker achieves the claim tampering, they can immediately elevate privileges and execute arbitrary administrative actions.
OpenCVE Enrichment