Incorrect Privilege Assignment in Keycloak - CVE-2026-9795

 

Incorrect Privilege Assignment in Keycloak - CVE-2026-9795

Published: June 29, 2026


Vulnerability identifier: #VU135691
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-9795
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Keycloak
Affected software:
Keycloak

Detailed vulnerability description

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper scope mapping enforcement in the Fine-Grained Admin Permissions (FGAPv2) feature when managing client scope mappings. A remote privileged user can assign arbitrary realm roles, including highly privileged roles, to a client's scope mapping to escalate privileges.

User interaction is required when a user accesses the modified client, causing the injected role to be projected into the authentication token.


How to mitigate CVE-2026-9795

Install security update from vendor's website.

Sources