Impact
A flaw in Keycloak’s Fine‑Grained Admin Permissions v2 lets a delegated administrator assign a composite role without the system checking the role’s internal permissions. The check fails to look inside composite roles, allowing a user with limited rights to grant a role that secretly contains full administrative control, thereby providing complete management access over the realm.
Affected Systems
Red Hat’s Build of Keycloak and Red Hat Single Sign‑On 7 are affected by this vulnerability. No specific version information was provided.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, and the EPSS score is not available, suggesting exploitation likelihood is undetermined. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to require an authenticated delegated admin who can assign roles; that is, the flaw can be exploited from within a compromised environment where users have limited administrative privileges. Because the assignment bypasses checks on composite roles, any attacker who can execute this assignment gains unrestricted realm‑management rights.
OpenCVE Enrichment