Impact
The vulnerability resides in the user update mechanism of the Keycloak Admin REST API. When Fine‑Grained Admin Permissions are enabled it performs a generic user profile update without enforcing the specific password reset authorization check. A delegated administrator lacking reset‑password rights can therefore change a user’s credentials and hijack that account. This flaw is a missing authorization control, classified as CWE‑862, and can lead to compromise of user confidentiality, integrity, and availability by allowing an attacker to subvert account security.
Affected Systems
The issue affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7 configurations. No specific version information is listed, so all builds using the affected API path should be verified.
Risk and Exploitability
The CVSS score of 6.6 indicates a medium severity, and the EPSS score is not available, so the likelihood of exploitation is currently unknown. The vulnerability is not listed in the CISA KEV catalog. Attackors need only delegated administrative rights and network access to the Admin REST API to exploit the flaw. Because the reduction path is to convert a generic update into credential takeover, the potential damage is significant and should be addressed promptly.
OpenCVE Enrichment