Description
A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account.
Published: 2026-09-24
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation – Account Takeover
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the user update mechanism of the Keycloak Admin REST API. When Fine‑Grained Admin Permissions are enabled it performs a generic user profile update without enforcing the specific password reset authorization check. A delegated administrator lacking reset‑password rights can therefore change a user’s credentials and hijack that account. This flaw is a missing authorization control, classified as CWE‑862, and can lead to compromise of user confidentiality, integrity, and availability by allowing an attacker to subvert account security.

Affected Systems

The issue affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7 configurations. No specific version information is listed, so all builds using the affected API path should be verified.

Risk and Exploitability

The CVSS score of 6.6 indicates a medium severity, and the EPSS score is not available, so the likelihood of exploitation is currently unknown. The vulnerability is not listed in the CISA KEV catalog. Attackors need only delegated administrative rights and network access to the Admin REST API to exploit the flaw. Because the reduction path is to convert a generic update into credential takeover, the potential damage is significant and should be addressed promptly.

Generated by OpenCVE AI on September 24, 2026 at 07:27 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Upgrade Keycloak or Red Hat Single Sign‑On to the latest release where the authorization check for password reset is enforced.
  • Re‑evaluate the delegated administrator role and remove or limit its ability to perform generic user updates for accounts that should not be updated.
  • If the environment allows, disable or reduce the granularity of Fine‑Grained Admin Permissions to limit exposure.
  • Enforce strict network controls on the Keycloak Admin REST API and monitor for anomalous user‑update traffic to early detect privilege misuse.

Generated by OpenCVE AI on September 24, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 24 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account.
Title Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission
First Time appeared Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
Weaknesses CWE-862
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Build Keycloak Red Hat Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-24T13:00:41.530Z

Reserved: 2026-09-24T05:38:16.365Z

Link: CVE-2026-97177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T06:17:04.380

Modified: 2026-09-24T13:17:19.247

Link: CVE-2026-97177

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-23T13:11:00Z

Links: CVE-2026-97177 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T07:30:16Z

Weaknesses