Security Advisory

CVE-2025-7784

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-18 13:48:45
Last updated 2026-05-06 16:48:58
Assigner redhat
State PUBLISHED

Description

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.