Impact
A flaw was discovered in the Admin REST API of Keycloak, an open‑source identity and access management system. The endpoint used to delete user credentials fails to enforce the fine‑grained reset‑password permission. As a result, a delegated administrator who is not permitted to reset passwords can delete a user’s password credential. When the credential is removed, the user is unable to authenticate, effectively locking the account.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. No specific version information is provided by the CNA, so any installation of these products that has not applied the corresponding patch may be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated request to the credential‑deletion API performed by a delegated administrator with insufficient privileges. Because the endpoint does not perform the necessary permission check, an attacker can delete a user’s credential without triggering a reset‑password action.
OpenCVE Enrichment