Authorization bypass through user-controlled key in Red Hat build of Keycloak - CVE-2026-14614
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to modify the contents of security tokens issued to end users.
The vulnerability exists due to a missing authorization check on referenced client scopes in the ClientResource component when assigning client scopes through the admin REST API. A remote user can attach or remove hidden client scopes to modify the contents of security tokens issued to end users.
Fine-Grained Admin Permissions v2 must be enabled, and exploitation requires knowledge of internal resource identifiers.