Impact
A flaw in Keycloak's admin REST API allows a delegated administrator to delete child roles from a composite role without proper authorization checks. This missing verification permits an attacker with limited administrative privileges to remove privileged roles they should not manage, thereby disrupting access controls for users and other administrators. The flaw manifests as an access control weakness identified as CWE‑862.
Affected Systems
The issue affects Red Hat's Build of Keycloak and related products such as Red Hat Data Grid 8, JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. All listed Red Hat vendor products that incorporate the vulnerable Keycloak component are impacted. Exact version details are not specified in the advisory, so any installation that includes a vulnerable release of these products should be considered at risk.
Risk and Exploitability
The CVSS score of 4.9 indicates a medium severity vulnerability. The EPSS score is reported as less than 1 %, implying a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The threat vector is essentially via the REST API, and the attacker must have delegated administrator privileges; no additional conditions are required. Because the exploit only removes privileged roles, immediate remediation is advisable to preserve the integrity of role assignments. Administrators should monitor for an official update, as no patch is currently available.
OpenCVE Enrichment