Bug 2537168 (CVE-2026-94000)

Summary: CVE-2026-94000 keycloak-services: keycloak-services: Delegated admin with manage-users can escalate to realm-admin via group membership
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aschwart, aszczucz, boliveir, drichtar, mposolda, pjindal, rmartinc, ssilvert, sthorger, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing a user to be added. This allows a delegated administrator with limited permissions to add themselves to a high-privilege group, potentially gaining full control over the entire realm.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-19 14:03:44 UTC
Improper Authorization in the Admin REST API group-membership endpoints (UserResource.joinGroup and the groups list in UsersResource.createUser) allows for privilege escalation. The root cause is a missing check to determine if a group confers administrative roles when a delegated administrator manages group memberships.
Exploitation requires the attacker to have a delegated administrator account with the manage-users role and the existence of a pre-configured group that maps to the realm-admin role. A successful attacker can add their own account or a new account to such a group, bypassing direct role assignment restrictions.
Concrete impact: The attacker gains full administrative control over the realm, allowing them to modify realm configurations, manage all users and roles, access sensitive credentials, and potentially cause a complete denial of service by deleting realm resources.