Fedora Account System
Red Hat Associate
Red Hat Customer
Improper Authorization in the Admin REST API group-membership endpoints (UserResource.joinGroup and the groups list in UsersResource.createUser) allows for privilege escalation. The root cause is a missing check to determine if a group confers administrative roles when a delegated administrator manages group memberships. Exploitation requires the attacker to have a delegated administrator account with the manage-users role and the existence of a pre-configured group that maps to the realm-admin role. A successful attacker can add their own account or a new account to such a group, bypassing direct role assignment restrictions. Concrete impact: The attacker gains full administrative control over the realm, allowing them to modify realm configurations, manage all users and roles, access sensitive credentials, and potentially cause a complete denial of service by deleting realm resources.