A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role mapper into any client. This action allows the user to bypass existing scope restrictions and inject the `realm-admin` role into generated tokens, resulting in privilege escalation and full administrative access to the realm.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-4629 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2450244 | Exploit Vendor Advisory |
Configurations
History
01 Jul 2026, 20:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Redhat build Of Keycloak
Redhat |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-4629 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2450244 - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:*:*:*:* |
30 Jun 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 13:18
Updated : 2026-07-01 20:25
NVD link : CVE-2026-4629
Mitre link : CVE-2026-4629
CVE.ORG link : CVE-2026-4629
JSON object : View
Products Affected
redhat
- build_of_keycloak
CWE
CWE-266
Incorrect Privilege Assignment
