Improper privilege management in Keycloak - CVE-2025-7784
Published: July 31, 2025
Vulnerability identifier: #VU113570
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7784
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to improper privilege management in the admin permission enforcement logic when FGAPv2 is enabled. A remote privileged user can edit their own role and gain unauthorized full access to realm configuration and user data.
Affected software
Keycloak
Red Hat build of Keycloak
Red Hat build of Keycloak
How to mitigate CVE-2025-7784
Install updates from vendor's website.
Keycloak - update to 26.2.6
Red Hat build of Keycloak - update to 26.2.6
Red Hat build of Keycloak - update to 26.2.6