CVE-2026-17526
largeMissing Authorization in Keycloak Allows Realm Admin Impersonation Takeover
A missing authorization check (CWE-862) in Keycloak's impersonation feature allows any user holding the impersonation role to impersonate a realm administrator account. The attack is carried out over the network by an authenticated user with the impersonation role who invokes impersonation against an administrator, yielding a session with full administrative privileges. The attacker thereby gains complete control of the realm, including the ability to manage users, clients, and roles, enabling persistence and compromise of every application the realm protects. Deployments are at risk where the impersonation role has been delegated beyond full realm administrators (for example to helpdesk or user-management staff); the available data does not specify affected or fixed version ranges. No public proof-of-concept is known, the flaw is not in CISA KEV, and there are no confirmed reports of exploitation in the wild.
What to do: Audit role mappings in each realm and revoke the impersonation role from any principal that is not a full realm administrator, since restricting that role is the primary mitigation. Upgrade Keycloak to the fixed release identified in the Red Hat security advisory for this CVE. Review admin-event logs for impersonation events targeting administrator accounts as a check for prior abuse.
| Red Hat Keycloak | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.