Impact
A flaw in the Dynamic Client Registration component of Keycloak allows an attacker with a standard user account and a limited Initial Access Token to write values to sensitive internal claim locations by exploiting the default DCR policy’s lack of claim‑path validation for User Property mappers. This gives the attacker the ability to forge administrative roles in their own access token, thereby taking over other clients, stealing confidential secrets, and potentially assuming full administrative control over the realm. The weakness is reflected in the CWE identifiers 284 and 551.
Affected Systems
Affected products include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack and Red Hat Single Sign‑On 7. The specific affected Keycloak builds are 26.4, 26.4.14, 26.6 and 26.6.5; Data Grid is version 8; Single Sign‑On is 7.0; the expansion pack version is not specified but all releases with the default DCR policy are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score is below 1 %, showing a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is remote, requiring only a valid user credential and a standard Initial Access Token. Once the attacker writes the forged administrative claims, they immediately elevate privileges and can perform arbitrary administrative actions on the realm.
OpenCVE Enrichment