Bug 2450245 (CVE-2026-4630)

Summary: CVE-2026-4630 keycloak: Keycloak: Unauthorized resource access and data modification via Insecure Direct Object Reference
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aschwart, aszczucz, boliveir, drichtar, mposolda, pjindal, rmartinc, security-response-team, ssilvert, sthorger, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-04-15   

Description OSIDB Bzimport 2026-03-23 08:12:48 UTC
Summary:

IDOR vulnerability in the Keycloak Authorization Services Protection
API endpoint /realms/{realm}/authz/protection/resource_set/{id} allows
authenticated clients to perform GET, PUT, and DELETE operations on
resources belonging to other Resource Servers within the same realm.
The endpoint fails to validate that the requested resource UUID
belongs to the calling Resource Server.

Requirements to exploit:

Attacker must possess valid client credentials for any Resource Server
with Authorization Services enabled in the target realm, and must know
or obtain the UUID of a resource belonging to another Resource Server.

Steps to reproduce:

1. Configure a Keycloak realm with two clients (clientA, clientB) with
Authorization Services enabled and allowRemoteResourceManagement=true
2. Create a resource under clientB and note its UUID
3. Obtain a client_credentials token for clientA using its client secret
4. Using clientA's token, send GET
/realms/{realm}/authz/protection/resource_set/{clientB-resource-uuid}
— returns 200 with clientB's resource data
5. Send PUT to the same endpoint with modified payload — returns 204,
resource is modified
6. Send DELETE to the same endpoint — note: triagers reported this
fails with an authorization error in 26.5.4, but GET and PUT succeed
7. Confirm modification by querying with clientB's token