Impact
A flaw in Keycloak's User-Managed Access implementation merges permissions when two users own resources of the same name. This improper merge grants an attacker scopes on another user's resource that were never meant to be shared. The weakness is a broken access control flaw (CWE-862).
Affected Systems
The vulnerability is disclosed for Red Hat Build of Keycloak and Red Hat Single Sign-On version 7. No specific version numbers are provided; any installation using the affected product lines is potentially impacted.
Risk and Exploitability
The flaw carries a CVSS score of 3.5, indicating low severity, and it is not listed in the CISA KEV catalog. The EPSS score is not available, implying no recent exploitation data. The likely attack vector is through the authorization token endpoint over the network, where an attacker can submit a permission ticket that triggers the accidental permission merge. Since no additional exploit prerequisites are described, the risk depends largely on an attacker’s ability to request tokens for the target resources.
OpenCVE Enrichment