Incorrect Privilege Assignment in Keycloak - CVE-2026-9795
Published: June 29, 2026
Keycloak
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper scope mapping enforcement in the Fine-Grained Admin Permissions (FGAPv2) feature when managing client scope mappings. A remote privileged user can assign arbitrary realm roles, including highly privileged roles, to a client's scope mapping to escalate privileges.
User interaction is required when a user accesses the modified client, causing the injected role to be projected into the authentication token.