Impact
A flaw in Keycloak’s administrative REST API allows a delegated administrator to delete a child role from a composite role without proper authorization checks, enabling an attacker with limited administrative permissions to remove privileged roles they are not authorized to manage. This results in loss of access for other users and administrators, undermining the integrity of role assignments.
Affected Systems
Red Hat’s Build of Keycloak and any products that embed it, including Red Hat Data Grid 8, the JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7, are impacted. The advisory does not provide specific version numbers, so any installation containing a vulnerable release of these products should be considered at risk.
Risk and Exploitability
The CVSS score of 4.9 indicates a medium severity vulnerability. EPSS is reported as less than 1 %, implying a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is via the REST API, requiring only delegated administrator privileges and no additional conditions. While the exploit only removes privileged roles, it threatens the security of role-based access control and warrants careful monitoring and timely remediation.
OpenCVE Enrichment