Authorization bypass through user-controlled key in Keycloak - CVE-2025-14777
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to modify or delete authorization resources belonging to another client.
The vulnerability exists due to improper access control in the ResourceSetService and PermissionTicketService admin API endpoints when handling authorization resource management requests. A remote privileged user can supply a valid resource ID belonging to another client to modify or delete its resources.
Exploitation is limited to resources within the same realm.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2025-14777
Red Hat build of Keycloak - update to 26.4.11