Impact
A flaw in the group policy evaluation logic of Keycloak incorrectly uses a text‑based prefix comparison to validate group membership when a policy is set to extend permissions to child groups. This allows a user who is a member of a different group that shares a common starting name to bypass security checks and gain unauthorized access to administrative functions or protected resources.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Data Grid 8, and Red Hat Single Sign‑On 7. No specific version numbers are listed, so any current installation using these products with the extendchildren group policy enabled may be exposed until a vendor fix is released.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the potential to obtain elevated privileges makes the impact high. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting a low current exploitation likelihood but not guaranteeing security. The likely attack vector requires an attacker to create or be a member of a group whose name shares a prefix with a protected group; the vulnerability is exploitable when the system performs this simple suffix check. If an attacker can set or influence group names, they can circumvent policy checks and gain admin access.
OpenCVE Enrichment