Impact
The flaw occurs when a user possessing the impersonation role can invoke Keycloak Services to impersonate any realm account, including administrators. This grants the attacker full administrative control over the realm, allowing manipulation of users, clients, and roles. It is a privilege escalation vulnerability (CWE-862) that compromises confidentiality, integrity, and availability of all realm resources.
Affected Systems
Red Hat build of Keycloak versions 26.4, 26.4.16, 26.6, and 26.6.7, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign-On 7 are affected. These include the CPEs cpe:/a:redhat:build_keycloak:26.4::el9, cpe:/a:redhat:build_keycloak:26.6::el9, cpe:/a:redhat:jboss_data_grid:8, cpe:/a:redhat:jbosseapxp, and cpe:/a:redhat:red_hat_single_sign_on:7.
Risk and Exploitability
The vulnerability is scored 7.2 on CVSS, indicating moderate‑to‑high severity, while the EPSS score is less than 1%, meaning the likelihood of exploitation is very low for the time being. It is not listed in the CISA KEV catalog. The flaw requires an attacker to have a valid user account with the impersonation role; the attacker can then use the Services API to impersonate a realm administrator. The attack vector is likely authenticated network access to the Keycloak Services endpoint, so it can be performed by remote actors that have legitimate credentials. Because no official workaround is available, deploying the security update is the only robust mitigation.
OpenCVE Enrichment