Bug 2537168 (CVE-2026-94000) - CVE-2026-94000 keycloak-services: keycloak-services: Delegated admin with manage-users can escalate to realm-admin via group membership
Summary: CVE-2026-94000 keycloak-services: keycloak-services: Delegated admin with man...
Keywords:
Status: NEW
Alias: CVE-2026-94000
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-19 14:03 UTC by OSIDB Bzimport
Modified: 2026-09-19 14:03 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-19 14:03:44 UTC
Improper Authorization in the Admin REST API group-membership endpoints (UserResource.joinGroup and the groups list in UsersResource.createUser) allows for privilege escalation. The root cause is a missing check to determine if a group confers administrative roles when a delegated administrator manages group memberships.
Exploitation requires the attacker to have a delegated administrator account with the manage-users role and the existence of a pre-configured group that maps to the realm-admin role. A successful attacker can add their own account or a new account to such a group, bypassing direct role assignment restrictions.
Concrete impact: The attacker gains full administrative control over the realm, allowing them to modify realm configurations, manage all users and roles, access sensitive credentials, and potentially cause a complete denial of service by deleting realm resources.


Note You need to log in before you can comment on or make changes to this bug.