Back

HIGH

Keycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-clients permission

Published Mar 26, 2026

Description

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when admin permissions are enabled at the realm level.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Red Hat statement

This issue was rated MODERATE. A privilege escalation flaw exists in Keycloak where an administrator with `manage-clients` permission can escalate privileges if "Admin Permissions" are enabled at the realm level.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 26, 2026
Updated Apr 2, 2026
Reserved Feb 24, 2026
CISA Vulnrichment
Updated Mar 30, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 24, 2026
ENISA EUVD
Assigner redhat
Published Mar 26, 2026
Updated Apr 2, 2026
Exploited since n/a
EUVD-2026-16307 GHSA-7XF9-4JFC-WGM4