Fedora Account System
Red Hat Associate
Red Hat Customer
A Missing Authorization vulnerability was found in the Keycloak full-scope-disabled client-policy executor. When the executor is configured with auto-configure disabled, it fails to properly validate client creation or update requests that omit the fullScopeAllowed field. Because the server defaults to fullScopeAllowed=true for non-consent clients, an attacker with delegated client creation privileges can bypass the intended restriction. Successful exploitation allows an attacker to create a client that possesses full scope access within the realm, even when a policy is active to prevent it. This results in the issuance of tokens containing role mappings that should have been restricted by the realm policy.