Keycloak is vulnerable to bad actors escalating privileges through its Fine-Grained Admin Permissions
Moderate severity
GitHub Reviewed
Published
Jul 18, 2025
to the GitHub Advisory Database
•
Updated Jul 21, 2025
Description
Published by the National Vulnerability Database
Jul 18, 2025
Published to the GitHub Advisory Database
Jul 18, 2025
Last updated
Jul 21, 2025
Reviewed
Jul 21, 2025
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions (FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.
References