Incorrect Privilege Assignment in Keycloak - CVE-2025-14778

 

Incorrect Privilege Assignment in Keycloak - CVE-2025-14778

Published: September 10, 2026


Vulnerability identifier: #VU148917
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14778
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper authorization in the UserManagedPermissionService (UMA Protection API) when updating or deleting UMA policies associated with multiple resources. A remote user can update a shared policy to modify authorization rules for resources owned by another user to escalate privileges.

Exploitation requires ownership of the first resource in the policy\'s resource list.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2025-14778

Install security update from vendor's website.

Keycloak - addressed in versions 26.2.13, 26.4.9, 26.5.3
Red Hat build of Keycloak - addressed in versions 26.2.13, 26.4.9

External References

Related Security Bulletins