ZeroHour

CVE-2026-17526

large

Missing Authorization in Keycloak Allows Realm Admin Impersonation Takeover

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

A missing authorization check (CWE-862) in Keycloak's impersonation feature allows any user holding the impersonation role to impersonate a realm administrator account. The attack is carried out over the network by an authenticated user with the impersonation role who invokes impersonation against an administrator, yielding a session with full administrative privileges. The attacker thereby gains complete control of the realm, including the ability to manage users, clients, and roles, enabling persistence and compromise of every application the realm protects. Deployments are at risk where the impersonation role has been delegated beyond full realm administrators (for example to helpdesk or user-management staff); the available data does not specify affected or fixed version ranges. No public proof-of-concept is known, the flaw is not in CISA KEV, and there are no confirmed reports of exploitation in the wild.

What to do: Audit role mappings in each realm and revoke the impersonation role from any principal that is not a full realm administrator, since restricting that role is the primary mitigation. Upgrade Keycloak to the fixed release identified in the Red Hat security advisory for this CVE. Review admin-event logs for impersonation events targeting administrator accounts as a check for prior abuse.

Affected
Red Hat Keycloak
Estimated exposure
large≈tens of thousands of Keycloak deployments plausibly affected, though only the subset where impersonation is delegated to non-administrators is exploitable — Keycloak is one of the most widely deployed open-source identity and access management servers, and public internet scans routinely surface tens of thousands of exposed instances, but the CVSS high-privilege prerequisite (PR:H — the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.