Description
A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what other permissions they contain, an administrator with limited rights can assign a role that secretly includes full administrative control. This allows the attacker to gain complete management access over the entire realm.
Published: 2026-09-25
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

A flaw in Keycloak’s Fine‑Grained Admin Permissions v2 lets a delegated administrator assign a composite role without the system checking the role’s internal permissions. The check fails to look inside composite roles, allowing a user with limited rights to grant a role that secretly contains full administrative control, thereby providing complete management access over the realm.

Affected Systems

Red Hat’s Build of Keycloak and Red Hat Single Sign‑On 7 are affected by this vulnerability. No specific version information was provided.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate severity, and the EPSS score is not available, suggesting exploitation likelihood is undetermined. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to require an authenticated delegated admin who can assign roles; that is, the flaw can be exploited from within a compromised environment where users have limited administrative privileges. Because the assignment bypasses checks on composite roles, any attacker who can execute this assignment gains unrestricted realm‑management rights.

Generated by OpenCVE AI on September 25, 2026 at 09:43 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a Keycloak version where the FGAP v2 composite role mapping check has been fixed. If a patch is not yet released, monitor Red Hat’s security advisories for a fix and apply it as soon as available.
  • Restrict delegated administrator roles to those that do not include role‑assignment permissions, or remove the ability to assign composite roles entirely to minimize privilege escalation risk.
  • Enable auditing and monitoring of role‑assignment events; review logs for unauthorized role grants and set up alerts to detect anomalous composite role assignments.

Generated by OpenCVE AI on September 25, 2026 at 09:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 25 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific role to a user. Because the check does not look inside composite roles to see what other permissions they contain, an administrator with limited rights can assign a role that secretly includes full administrative control. This allows the attacker to gain complete management access over the entire realm.
Title Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-285
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T07:39:51.903Z

Reserved: 2026-09-23T09:42:55.806Z

Link: CVE-2026-96448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-25T08:16:42.437

Modified: 2026-09-25T13:26:09.190

Link: CVE-2026-96448

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-25T07:14:47Z

Links: CVE-2026-96448 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T09:45:17Z

Weaknesses