Authorization bypass through user-controlled key in Keycloak - CVE-2025-14777

 

Authorization bypass through user-controlled key in Keycloak - CVE-2025-14777

Published: September 10, 2026


Vulnerability identifier: #VU148927
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14777
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify or delete authorization resources belonging to another client.

The vulnerability exists due to improper access control in the ResourceSetService and PermissionTicketService admin API endpoints when handling authorization resource management requests. A remote privileged user can supply a valid resource ID belonging to another client to modify or delete its resources.

Exploitation is limited to resources within the same realm.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2025-14777

Install security update from vendor's website.

Keycloak - update to 26.5.6
Red Hat build of Keycloak - update to 26.4.11

External References

Related Security Bulletins