Bug 2507409 (CVE-2026-17526) - CVE-2026-17526 keycloak-services: keycloak-services: Privilege escalation via impersonation role allows takeover of realm administrator accounts
Summary: CVE-2026-17526 keycloak-services: keycloak-services: Privilege escalation via...
Keywords:
Status: NEW
Alias: CVE-2026-17526
Deadline: 2026-10-22
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-27 08:40 UTC by OSIDB Bzimport
Modified: 2026-09-16 13:08 UTC (History)
29 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-27 08:40:14 UTC
A flaw was found in Keycloak. A user holding only the impersonation realm-management client role can impersonate any enabled, non-service-account user in the realm, including full realm administrators. The impersonation endpoint restricts service accounts as targets but performs no privilege-level check on the target user. After impersonating an administrator, the attacker obtains a valid SSO session and can exchange it for a fully signed access token via a standard OIDC authorization-code flow, gaining complete administrative control over the realm (read/write all users, clients, roles, password resets). The impersonation role is designed as a lesser delegation for support staff, and this flaw defeats that separation.


Note You need to log in before you can comment on or make changes to this bug.