Impact
A flaw in the Admin REST API of Keycloak allows a delegated administrator who has the manage‑users permission to add themselves to a group that grants administrative rights, thereby elevating privileges to realm‑administrator control. This is a classic example of a missing authorization check (CWE-862) that can lead to full control over the realm.
Affected Systems
Affected products include Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. Specific version numbers are not listed, implying that any deployed instance of these products may be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.6, indicating moderate severity, and it is not listed in the CISA KEV catalog. EPSS data is unavailable, so the likelihood of exploitation cannot be precisely quantified, but the attack will target the Admin REST API, requiring that an attacker already possess delegated administrator access with the manage‑users privilege. Once the endpoint is reached, the privilege escalation is automated and immediately grants realm‑administrator rights. Unfortunately, Red Hat does not provide a functional workaround; therefore, organizations should focus on restricting delegated admin privileges or applying a patch when released.
OpenCVE Enrichment