Description
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Realm Administrator
Action: Apply Patch
AI Analysis

Impact

The flaw occurs when a user possessing the impersonation role can invoke Keycloak Services to impersonate any realm account, including administrators. This grants the attacker full administrative control over the realm, allowing manipulation of users, clients, and roles. It is a privilege escalation vulnerability (CWE-862) that compromises confidentiality, integrity, and availability of all realm resources.

Affected Systems

Red Hat build of Keycloak versions 26.4, 26.4.16, 26.6, and 26.6.7, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign-On 7 are affected. These include the CPEs cpe:/a:redhat:build_keycloak:26.4::el9, cpe:/a:redhat:build_keycloak:26.6::el9, cpe:/a:redhat:jboss_data_grid:8, cpe:/a:redhat:jbosseapxp, and cpe:/a:redhat:red_hat_single_sign_on:7.

Risk and Exploitability

The vulnerability is scored 7.2 on CVSS, indicating moderate‑to‑high severity, while the EPSS score is less than 1%, meaning the likelihood of exploitation is very low for the time being. It is not listed in the CISA KEV catalog. The flaw requires an attacker to have a valid user account with the impersonation role; the attacker can then use the Services API to impersonate a realm administrator. The attack vector is likely authenticated network access to the Keycloak Services endpoint, so it can be performed by remote actors that have legitimate credentials. Because no official workaround is available, deploying the security update is the only robust mitigation.

Generated by OpenCVE AI on September 18, 2026 at 00:14 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the Red Hat security updates issued in RHSA‑2026:68276, RHSA‑2026:68277, RHSA‑2026:68278, and RHSA‑2026:68280 to all affected Keycloak, Single Sign‑On, Data Grid, and JBoss EAP Expansion Pack installations.
  • Until the update is applied, remove the impersonation role from all non‑essential users as a temporary containment measure.
  • After updating, audit role assignments and enforce a least‑privilege policy so that only trusted users retain the impersonation role.

Generated by OpenCVE AI on September 18, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack
Vendors & Products Redhat build Of Keycloak
Redhat data Grid 8
Redhat jboss Enterprise Application Platform Expansion Pack

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On

Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
Title Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:26.4::el9
cpe:/a:redhat:build_keycloak:26.6::el9
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid 8 Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-16T18:09:00.607Z

Reserved: 2026-07-27T08:39:49.751Z

Link: CVE-2026-17526

cve-icon Vulnrichment

Updated: 2026-09-16T16:01:31.887Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T16:17:04.647

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-17526

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T12:58:17Z

Links: CVE-2026-17526 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:46Z

Weaknesses