A flaw was found in Keycloaks Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a clients scope mapping. This bypasses intended security controls, allowing the injected role to be projected into a users authentication token when they access the modified client. This could lead to unauthorized privilege escalation within the Keycloak realm.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Build_of_keycloak | Redhat | - (including) | - (including) |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-operator-bundle:26.4.13-1 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-rhel9:26.4-19 | * |
| Red Hat build of Keycloak 26.4 | RedHat | rhbk/keycloak-rhel9-operator:26.4-19 | * |
| Red Hat build of Keycloak 26.4.13 | RedHat | rhbk/keycloak-rhel9 | * |
| Red Hat build of Keycloak 26.6 | RedHat | rhbk/keycloak-operator-bundle:26.6.4-2 | * |
| Red Hat build of Keycloak 26.6 | RedHat | rhbk/keycloak-rhel9:26.6-8 | * |
| Red Hat build of Keycloak 26.6 | RedHat | rhbk/keycloak-rhel9-operator:26.6-8 | * |
| Red Hat build of Keycloak 26.6.4 | RedHat | rhbk/keycloak-rhel9 | * |