Incorrect Privilege Assignment in Keycloak - CVE-2025-14778
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper authorization in the UserManagedPermissionService (UMA Protection API) when updating or deleting UMA policies associated with multiple resources. A remote user can update a shared policy to modify authorization rules for resources owned by another user to escalate privileges.
Exploitation requires ownership of the first resource in the policy\'s resource list.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-14778
Red Hat build of Keycloak - addressed in versions 26.2.13, 26.4.9