Dettaglio notizia

Data 13/07/2026
Titolo Keycloak fixes FGAPv2 privilege escalation and multiple access control flaws
Contesto Keycloak disclosed and patched a high-severity privilege escalation flaw, CVE-2026-9795, in its Fine-Grained Admin Permissions v2 (FGAPv2) feature after researchers reported that a delegated administrator could bypass missing authorization checks in the admin REST API and add arbitrary realm roles to a client’s scope mapping. That weakness allowed limited administrators to inject elevated roles such as realm-admin into tokens later issued to users authenticating through the affected client, creating a path to downstream privilege escalation in deployments running Keycloak 26.2.0 and later with FGAPv2 enabled.

The issue was later listed as fixed in Keycloak release 26.6.4, alongside several other security bugs including CVE-2026-9099, CVE-2026-9083, CVE-2026-9086, CVE-2026-9705, CVE-2026-9799, CVE-2026-9800, and CVE-2026-11800. Red Hat also shipped security updates for its Keycloak 26.4.11 images and operator on OpenShift, addressing a broad set of vulnerabilities across the Admin REST API, Account REST API, OIDC dynamic client registration, UMA authorization, token handling, redirect validation, and scope processing, with impacts ranging from information disclosure and SSRF to account takeover, policy bypass, and denial of service.
Fonte https://mallory.ai/stories/019f4df5-0b3a-78dd-b762-c6d2c348e533
Discussione? Parliamone sul Forum