Keycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-clients permission
Published Mar 26, 2026
7.2
HIGHCVSS 3.1
EPSS 0.53%
Description
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.
Affected products
-
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected |
|
- n/a
- 8.0.0
- n/a
- 7.0
No data.
Red Hat build of Keycloak 26.4
rhbk/keycloak-operator-bundle:26.4.11-1
Fixed · RHSA-2026:6478
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9-operator:26.4-14
Fixed · RHSA-2026:6478
Red Hat build of Keycloak 26.4
rhbk/keycloak-rhel9:26.4-14
Fixed · RHSA-2026:6478
Red Hat build of Keycloak 26.4.11
rhbk/keycloak-rhel9
Fixed · RHSA-2026:6477
Red Hat JBoss Enterprise Application Platform 8
keycloak-services
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
keycloak-services
Fix deferred
Red Hat Single Sign-On 7
keycloak-services
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-operator-bundle:26.4.11-1 | Fixed | RHSA-2026:6478 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9-operator:26.4-14 | Fixed | RHSA-2026:6478 |
| Red Hat build of Keycloak 26.4 | rhbk/keycloak-rhel9:26.4-14 | Fixed | RHSA-2026:6478 |
| Red Hat build of Keycloak 26.4.11 | rhbk/keycloak-rhel9 | Fixed | RHSA-2026:6477 |
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-services | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-services | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | keycloak-services | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This issue was rated MODERATE. A privilege escalation flaw exists in Keycloak where an administrator with `manage-clients` permission can escalate privileges if "Admin Permissions" are enabled at the realm level.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (10)
- https://access.redhat.com/errata/RHSA-2026:6477 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:6478 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-3121 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2442277 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16307 Advisory
- https://github.com/advisories/GHSA-7xf9-4jfc-wgm4 Advisory
- https://github.com/keycloak/keycloak/commit/79ab3110a257fb8d6f1a664c916687128094ed01
- https://github.com/keycloak/keycloak/issues/46719
- https://nvd.nist.gov/vuln/detail/CVE-2026-3121
- https://www.cve.org/CVERecord?id=CVE-2026-3121
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:6477 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:6478 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-3121 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2442277 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16307 | Advisory | |
| https://github.com/advisories/GHSA-7xf9-4jfc-wgm4 | Advisory | |
| https://github.com/keycloak/keycloak/commit/79ab3110a257fb8d6f1a664c916687128094ed01 | ||
| https://github.com/keycloak/keycloak/issues/46719 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2026-3121 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-3121 |
Change history (0)
No recorded changes yet.