Beveiligingsadvies

CVE-2026-4629

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-30 12:00:28
Laatst bijgewerkt 2026-08-05 18:45:34
Toegewezen door redhat
CVSS-score 6.5
Status PUBLISHED

Beschrijving

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege escalation and full administrative access to the realm.