Improper privilege management in Keycloak - CVE-2025-7784

 

Improper privilege management in Keycloak - CVE-2025-7784

Published: July 31, 2025


Vulnerability identifier: #VU113570
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-7784
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to improper privilege management in the admin permission enforcement logic when FGAPv2 is enabled. A remote privileged user can edit their own role and gain unauthorized full access to realm configuration and user data.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2025-7784

Install updates from vendor's website.

Keycloak - update to 26.2.6
Red Hat build of Keycloak - update to 26.2.6

External References

Related Security Bulletins