Description
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control. Successful exploitation could lead to the exposure of client credentials or the redirection of administrative login attempts to malicious sites.
Published: 2026-09-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized client configuration access through cross-realm requests
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the Admin REST API of Keycloak where the per-request in-memory cache resolves clients by unique identifier without checking that the client belongs to the realm specified in the request path. An administrator with limited privileges can therefore read or modify sensitive client configurations that belong to the master realm by performing requests through a realm they control. This can lead to exposure of client credentials or the redirection of administrative login attempts to malicious sites.

Affected Systems

The affected products are Red Hat Build of Keycloak and Red Hat Single Sign-On 7. No specific version numbers are provided, but the flaw applies to all releases of these products that have not been patched by Red Hat.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, suggesting that public exploitation is not currently reported. However, the vulnerability can be exploited remotely over the REST API by anyone who has administrative privileges in a realm, allowing the attacker to access client data in other realms. Because no official patch is available at present, the risk remains moderate to potentially high until a fix is deployed.

Generated by OpenCVE AI on September 21, 2026 at 07:57 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • No practical workaround is available; the CNA indicates current options do not meet security criteria.
  • Restrict administrators' role scopes so they cannot perform cross-realm client read/write by removing access to the master realm admin API.
  • Disable or block the Admin REST API endpoints that allow client read/write until a patch is released, especially for sensitive operations.
  • Monitor audit logs for unauthorized cross-realm API calls and review configuration changes across realms regularly.
  • Apply any available patch for Red Hat Build of Keycloak or Red Hat Single Sign-On 7 once released by Red Hat.

Generated by OpenCVE AI on September 21, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 21 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifying if the client belongs to the realm specified in the request path. This allows an administrator with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a realm they control. Successful exploitation could lead to the exposure of client credentials or the redirection of administrative login attempts to malicious sites.
Title Keycloak-services: keycloak-services: cross-realm client read/write via request-level cache missing realm ownership check
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T20:46:32.823Z

Reserved: 2026-09-21T05:54:04.908Z

Link: CVE-2026-94215

cve-icon Vulnrichment

Updated: 2026-09-21T19:40:20.451Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-21T07:16:54.307

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-94215

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-20T01:54:31Z

Links: CVE-2026-94215 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T08:00:08Z

Weaknesses